LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31874

CVE-2026-31874 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 11, 2026

Taskosaur - Broken Access Control

Published: March 11, 2026Updated: March 11, 2026Remote Exploitable

Overview

Taskosaur 1.0.0 contains a broken access control vulnerability caused by improper validation of the role parameter during user registration, letting unauthenticated attackers create accounts with SUPER_ADMIN privileges, exploit requires no authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 9.0%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can create fully privileged administrative accounts, leading to complete system compromise.

Mitigation

Update to the latest version with proper role validation and enforcement.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 11, 2026

šŸ”“ CVE-2026-31874 - Critical (9.8) Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or restrict the role parameter during the user registration process. An attacker can man... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-31874/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 11, 2026

šŸ”“ CVE-2026-31874 - Critical (9.8) Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or restrict the role parameter during the user registration process. An attacker can man... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-31874/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-31874
Severity
Critical
CVSS Score
9.8
Type
broken_access_control
Status
new
EPSS
9.0%
Social Posts
2

CWE

  • CWE-284

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

9.0%Probability of exploitation in the next 30 days