CVE-2026-25531 PUBLISHED

Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects

Assigner: GitHub_M
Reserved: 02.02.2026 Published: 13.02.2026 Updated: 13.02.2026

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowing authenticated users to duplicate tasks into projects they cannot access. This vulnerability is fixed in 1.2.50.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 4.3

Product Status

Vendor kanboard
Product kanboard
Versions
  • Version < 1.2.50 is affected

References

Problem Types

  • CWE-862: Missing Authorization CWE