User Enumeration Vulnerability in 4gaBoards Project Management Software by RARgames
CVE-2026-53959

6.5MEDIUM

Key Information:

Vendor

Rargames

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-53959?

The 4gaBoards project management software, prior to version 3.3.9, is vulnerable to user enumeration attacks. Authenticated users can exploit the API endpoints to enumerate account information for all users. Specifically, through the GET /api/users endpoint, malicious actors can access sensitive information such as email addresses, phone numbers, organization details, names, admin status, and linked Single Sign-On (SSO) emails. This lack of request-specific authorization and response sanitization facilitates potential privacy breaches and targeted phishing attempts. The issue has been addressed in version 3.3.9.

Affected Version(s)

4gaBoards < 3.3.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.