Authenticated SQL Injection Vulnerability in Kanboard Project Management Software
CVE-2026-33058

8.4HIGH

Key Information:

Vendor

Kanboard

Status
Vendor
CVE Published:
18 March 2026

What is CVE-2026-33058?

Kanboard is a project management tool that implements the Kanban methodology. It has been discovered that versions prior to 1.2.51 contain an authenticated SQL injection vulnerability. This issue allows attackers with permissions to add users to a project to exploit the vulnerability, enabling them to extract sensitive information from the entire Kanboard database. Upgrading to version 1.2.51 or later resolves this security flaw.

Affected Version(s)

kanboard < 1.2.51

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.