---
id: CVE-2026-58660
title: >-
  Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save()
  method (used by the kanban board drag-and-drop endpoint) validates the
  caller's role on the attacker-supplied project_id but never verifies that the
  supplied ta…
summary: >-
  Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save()
  method (used by the kanban board drag-and-drop endpoint) validates the
  caller's role on the attacker-supplied project_id but never verifies that the
  supplied ta…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-639
vendor: kanboard
product: kanboard
affected:
  - kanboard < 1.2.52
published: '2026-07-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:23.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58660'
references:
  - url: >-
      https://github.com/kanboard/kanboard/commit/564cc30e1e360959572e01e158734d9475c05903
    label: disclosure@vulncheck.com
  - url: 'https://github.com/kanboard/kanboard/issues/5852'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/kanboard/kanboard/pull/5853'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/kanboard-boardajaxcontroller-missing-ownership-check-via-drag-and-drop
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-15T17:53:56.446519Z'
epss: 0.00504
epssPercentile: 0.41144
ingestedAt: '2026-10-08T16:52:14.700Z'
---

## Overview

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential integers shared across the entire instance, any authenticated user who is a member of at least one project can enumerate and move (corrupt/hide) tasks belonging to any other project on the same instance, including private projects they have no membership or role on.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
