CVE 9.1 CRITICAL

v2board / Xboard Authentication Token Exposure via loginWithMailLink_CVE-2026-39912

9.1 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges.

Basic Information

ID CVE-2026-39912
Source VulnCheck
Published Apr 9, 2026 at 18:35
Modified Apr 9, 2026 at 18:51

Affected Product

Vendor v2board
Product v2board
Version 1.6.1
Affected Versions v2board v2board 1.6.1
v2board v2board bdb10bed32c5f37df2f0872c3cb354e9b7a293bd
cedar2025 Xboard 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.