User Enumeration Vulnerability in 4gaBoards Project Management Software by RARgames
CVE-2026-53959
6.5MEDIUM
What is CVE-2026-53959?
The 4gaBoards project management software, prior to version 3.3.9, is vulnerable to user enumeration attacks. Authenticated users can exploit the API endpoints to enumerate account information for all users. Specifically, through the GET /api/users endpoint, malicious actors can access sensitive information such as email addresses, phone numbers, organization details, names, admin status, and linked Single Sign-On (SSO) emails. This lack of request-specific authorization and response sanitization facilitates potential privacy breaches and targeted phishing attempts. The issue has been addressed in version 3.3.9.
Affected Version(s)
4gaBoards < 3.3.9
