CVE Explorer
CVE-2026-25924
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application correctly hides the plugin installation interface when the PLUGIN_INSTALLER configuration is set to false, the underlying backend endpoint fails to verify this security setting. An attacker can exploit this oversight to force the server to download and
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"kanboard","vendor":"kanboard","versions":[{"status":"affected","version":"< 1.2.50"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d3c94ed5476d18d8f009a3acff1bdbf8a83e04bf711a2991ffa60412c0f54aac · sha256:d4c51bff407cfaf7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d3c94ed5476d18d8f009a3acff1bdbf8a83e04bf711a2991ffa60412c0f54aac · sha256:d4c51bff407cfaf7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d3c94ed5476d18d8f009a3acff1bdbf8a83e04bf711a2991ffa60412c0f54aac · sha256:d4c51bff407cfaf7… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/kanboard/kanboard/commit/b9ada89b1a64034612fc4262b88c42458c0d6ee4","tags":["x_refsource_MISC"],"url":"https://github.com/kanboard/kanboard/commit/b9ada89b1a64034612fc4262b88c42458c0d6ee4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d3c94ed5476d18d8f009a3acff1bdbf8a83e04bf711a2991ffa60412c0f54aac · sha256:d4c51bff407cfaf7… · /containers/cna/references/1
{"name":"https://github.com/kanboard/kanboard/releases/tag/v1.2.50","tags":["x_refsource_MISC"],"url":"https://github.com/kanboard/kanboard/releases/tag/v1.2.50"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d3c94ed5476d18d8f009a3acff1bdbf8a83e04bf711a2991ffa60412c0f54aac · sha256:d4c51bff407cfaf7… · /containers/cna/references/2
{"name":"https://github.com/kanboard/kanboard/security/advisories/GHSA-grch-p7vf-vc4f","tags":["x_refsource_CONFIRM"],"url":"https://github.com/kanboard/kanboard/security/advisories/GHSA-grch-p7vf-vc4f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d3c94ed5476d18d8f009a3acff1bdbf8a83e04bf711a2991ffa60412c0f54aac · sha256:d4c51bff407cfaf7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.