Pre-Account Takeover Vulnerability in 4gaBoards by RARgames
CVE-2026-50191

8.8HIGH

Key Information:

Vendor

Rargames

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-50191?

4gaBoards, a project management tool, has a vulnerability that allows attackers to create an unverified account using a victim's email when certain registration options are enabled. Specifically, if registration and Single Sign-On (SSO) via platforms like Google, GitHub, or Microsoft is configured, attackers can link to the victim's account without verification, granting access to the victim's data and projects. This issue has been resolved in version 3.3.8.

Affected Version(s)

4gaBoards < 3.3.8

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.