CVE-2026-39912

CRITICAL

v2board / Xboard Authentication Token Exposure via loginWithMailLink

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-39912. PoCs published by Chocapikk.

AI-analyzed exploit summary The repository contains a functional exploit for CVE-2026-39912, which leverages a magic link token leak in the `loginWithMailLink` endpoint of Xboard/V2Board to achieve unauthenticated account takeover. The exploit demonstrates the vulnerability by requesting a magic link for a target email and using the leaked token to authenticate and dump user data.

Description

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges.

Exploits (1)

nomisec WORKING POC
by Chocapikk · poc
https://github.com/Chocapikk/CVE-2026-39912

The repository contains a functional exploit for CVE-2026-39912, which leverages a magic link token leak in the `loginWithMailLink` endpoint of Xboard/V2Board to achieve unauthenticated account takeover. The exploit demonstrates the vulnerability by requesting a magic link for a target email and using the leaked token to authenticate and dump user data.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: V2Board >= 1.6.1 through 1.7.4, Xboard all versions through 0.1.9+
No auth needed
Prerequisites: login_with_mail_link_enable must be enabled in admin settings · a valid registered email address
devstral-2 · analyzed Apr 10, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.0010
EPSS Percentile 27.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-201
Status published
Products (4)
cedar2025/Xboard < 0.1.9
cedar2025/Xboard 121511523f04882ec0c7447acd9b8ebcb8a47957
v2board/v2board 1.6.1 - 1.7.4
v2board/v2board bdb10bed32c5f37df2f0872c3cb354e9b7a293bd - 0ca47622a50116d0ddd7ffb316b157afb57d25e8
Published Apr 09, 2026
Tracked Since Apr 10, 2026