CVE-2026-39912 Details
Description
V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges.
A vulnerability exists in V2Board versions 1.6.1 prior to 1.7.4 and in Xboard versions through 0.1.9. When the 'login_with_mail_link_enable' feature is active, the 'loginWithMailLink' endpoint exposes authentication tokens in the HTTP response body. Unauthenticated attackers can exploit this by sending a POST request to the 'loginWithMailLink' endpoint with a known email address. The response includes a magic login link containing a verification token, which can be exchanged at the 'token2Login' endpoint for a valid bearer token. This token grants full access to the user's account, including admin privileges.
Users can update to V2Board versions 1.7.5 or later, or to Xboard versions 0.2.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 9, 2026CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| V2Board | All versions |
CPE
Remediation
| |
| Xboard | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2026 | New CVE Received | [email protected] |
Volerion