Unrated severityNVD Advisory· Published Mar 18, 2026· Updated Mar 18, 2026
Kanboard's privilege escalation via mass assignment in user invite registration allows any invited user to become admin
CVE-2026-29056
Description
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (UserInviteController::register()) accepts all POST parameters and passes them to UserModel::create() without filtering out the role field. An attacker who receives an invite link can inject role=app-admin in the registration form to create an administrator account. Version 1.2.51 fixes the issue.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/kanboard/kanboard/security/advisories/GHSA-2jvj-q44v-6p3xmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.