← Voltar para CVEs
CVE-2026-21880
MEDIUM5.3
Descricao
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
Detalhes CVE
Pontuacao CVSS v3.15.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado1/8/2026
Ultima modificacao1/20/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
kanboard:kanboard
Fraquezas (CWE)
CWE-90CWE-200
Referencias
https://github.com/kanboard/kanboard/commit/dd374079f7c2d1dab74c1680960e684ff8668586(security-advisories@github.com)
https://github.com/kanboard/kanboard/releases/tag/v1.2.49(security-advisories@github.com)
https://github.com/kanboard/kanboard/security/advisories/GHSA-v66r-m28r-wmq7(security-advisories@github.com)
https://github.com/kanboard/kanboard/security/advisories/GHSA-v66r-m28r-wmq7(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.