{"id":"CVE-2026-58660","title":"Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied ta…","summary":"Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied ta…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-639"],"vendor":"kanboard","product":"kanboard","affected":["kanboard < 1.2.52"],"published":"2026-07-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:23.733","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-58660","references":[{"url":"https://github.com/kanboard/kanboard/commit/564cc30e1e360959572e01e158734d9475c05903","label":"disclosure@vulncheck.com"},{"url":"https://github.com/kanboard/kanboard/issues/5852","label":"disclosure@vulncheck.com"},{"url":"https://github.com/kanboard/kanboard/pull/5853","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/kanboard-boardajaxcontroller-missing-ownership-check-via-drag-and-drop","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-15T17:53:56.446519Z"},"epss":0.00504,"epssPercentile":0.41144,"ingestedAt":"2026-10-08T16:52:14.700Z","slug":"CVE-2026-58660","body":"## Overview\n\nKanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential integers shared across the entire instance, any authenticated user who is a member of at least one project can enumerate and move (corrupt/hide) tasks belonging to any other project on the same instance, including private projects they have no membership or role on.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}