LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-29056

CVE-2026-29056 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 18, 2026

Kanboard - Broken Access Control

Published: March 18, 2026Updated: March 18, 2026PoC AvailableRemote Exploitable

Overview

Kanboard < 1.2.51 contains a broken access control vulnerability caused by unfiltered 'role' parameter in UserInviteController::register(), letting attackers with invite links create administrator accounts, exploit requires an invite link.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 5.3%(Probability of exploitation in next 30 days)

Impact

An attacker with an invite link can create an administrator account, leading to full system control.

Mitigation

Upgrade to version 1.2.51 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 18, 2026

🟠 CVE-2026-29056 - High (8.8) Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-29056/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 18, 2026

🟠 CVE-2026-29056 - High (8.8) Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-29056/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-29056
Severity
High
CVSS Score
8.8
Type
broken_access_control
Status
confirmed
EPSS
5.3%
Social Posts
2

CWE

  • CWE-915

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

5.3%Probability of exploitation in the next 30 days