CVE-2026-25924 Details
Description
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application correctly hides the plugin installation interface when the PLUGIN_INSTALLER configuration is set to false, the underlying backend endpoint fails to verify this security setting. An attacker can exploit this oversight to force the server to download and install a malicious plugin, leading to arbitrary code execution. This vulnerability is fixed in 1.2.50.
A remote code execution vulnerability has been identified in Kanboard project management software, specifically in versions prior to 1.2.50. This vulnerability arises from a security control bypass that allows an authenticated administrator to exploit the plugin installation feature. Although the application correctly disables the plugin installation interface when the 'PLUGIN_INSTALLER' configuration is set to false, the backend endpoint does not verify this setting. As a result, an attacker can manipulate the server into downloading and installing a malicious plugin, which is then executed, leading to arbitrary code execution on the server.
Users are advised to update Kanboard to version 1.2.50 or later, where this vulnerability has been patched. The update can be downloaded from the Kanboard GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kanboard/kanboard/commit/b9ada89b1a64034612fc4262b88c42458c0d6ee4 | [email protected] | Patch |
| https://github.com/kanboard/kanboard/releases/tag/v1.2.50 | [email protected] | ProductRelease Notes |
| https://github.com/kanboard/kanboard/security/advisories/GHSA-grch-p7vf-vc4f | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kanboard kanboard | < 1.2.50 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2026 | Initial Analysis | [email protected] |
| Feb 11, 2026 | New CVE Received | [email protected] |