CVE-2026-25531 - Vulnerability Analysis
MediumCVSS: 4.3Last Updated: February 13, 2026
Kanboard - Broken Access Control
Published: February 13, 2026Updated: February 13, 2026PoC AvailableRemote Exploitable
Overview
Kanboard prior to 1.2.50 contains a broken access control vulnerability caused by lack of permission validation in TaskCreationController::duplicateProjects() endpoint, letting authenticated users duplicate tasks into unauthorized projects.
Severity & Score
Severity: Medium
CVSS Score: 4.3
Impact
Authenticated users can duplicate tasks into projects they do not have access to, potentially leading to unauthorized data manipulation.
Mitigation
Upgrade to version 1.2.50 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-25531
- Severity
- Medium
- CVSS Score
- 4.3
- Type
- broken_access_control
- Status
- confirmed
CWE
- CWE-862
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N