CVE-2026-21880
MEDIUMKanboard < 1.2.49 - Information Disclosure
Title source: ruleDescription
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
Exploits (1)
github
WORKING POC
1 stars
by HUSEYNKHANLI · pythonpoc
https://github.com/HUSEYNKHANLI/CVEs/tree/main/CVE-2026-21880
References (3)
Scores
CVSS v3
5.3
EPSS
0.0013
EPSS Percentile
31.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
CWE-90
Status
published
Products (1)
kanboard/kanboard
< 1.2.49
Published
Jan 08, 2026
Tracked Since
Feb 18, 2026