CVE 8.5 HIGH

Kanboard is Missing Access Control on Plugin Installation leading to Administrative RCE_CVE-2026-25924

8.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Description

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application correctly hides the plugin installation interface when the PLUGIN_INSTALLER configuration is set to false, the underlying backend endpoint fails to verify this security setting. An attacker can exploit this oversight to force the server to download and install a malicious plugin, leading to arbitrary code execution. This vulnerability is fixed in 1.2.50.

AI Analysis

Security control bypass vulnerability allowing authenticated administrators to achieve full Remote Code Execution (RCE) via malicious plugin installation

Basic Information

ID CVE-2026-25924
Source GitHub_M
Published Feb 11, 2026 at 20:43

Affected Product

Vendor kanboard
Product kanboard
Version < 1.2.50
Affected Versions kanboard kanboard < 1.2.50

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor Kanboard
Product Kanboard
Version < 1.2.50

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.