CVE 9.1 CRITICAL

Kanboard is Vulnerable to Reverse Proxy Authentication Bypass_CVE-2026-21881

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse proxy. An attacker can impersonate any user, including administrators, by simply sending a spoofed HTTP header. This issue is fixed in version 1.2.49.

AI Analysis

Critical authentication bypass vulnerability in Kanboard when REVERSE_PROXY_AUTH is enabled, allowing attackers to impersonate users by sending spoofed HTTP headers.

Basic Information

ID CVE-2026-21881
Source GitHub_M
Published Jan 8, 2026 at 01:08

Affected Product

Vendor kanboard
Product kanboard
Version < 1.2.49
Affected Versions kanboard kanboard < 1.2.49

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor Kanboard
Product Kanboard
Version 1.2.48 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.