CVE-2026-29056 PUBLISHED

Kanboard's privilege escalation via mass assignment in user invite registration allows any invited user to become admin

Assigner: GitHub_M
Reserved: 03.03.2026 Published: 18.03.2026 Updated: 18.03.2026

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (UserInviteController::register()) accepts all POST parameters and passes them to UserModel::create() without filtering out the role field. An attacker who receives an invite link can inject role=app-admin in the registration form to create an administrator account. Version 1.2.51 fixes the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:N/SA:N/E:P
CVSS Score: 7

Product Status

Vendor kanboard
Product kanboard
Versions
  • Version < 1.2.51 is affected

References

Problem Types

  • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes CWE