9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse proxy. An attacker can impersonate any user, including administrators, by simply sending a spoofed HTTP header. This issue is fixed in version 1.2.49.
AI Analysis
Critical authentication bypass vulnerability in Kanboard when REVERSE_PROXY_AUTH is enabled, allowing attackers to impersonate users by sending spoofed HTTP headers.
Basic Information
ID
CVE-2026-21881
Source
GitHub_M
Published
Jan 8, 2026 at 01:08
Affected Product
Vendor
kanboard
Product
kanboard
Version
< 1.2.49
Affected Versions
kanboard kanboard < 1.2.49
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Kanboard
Product
Kanboard
Version
1.2.48 and below