CVE-2026-56774
MEDIUMKanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID
Title source: cnaDescription
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessions. Attackers can enumerate sequential session IDs and mass-invalidate persistent login sessions of any user, including administrators, forcing re-authentication and causing denial of service.
References (4)
Core 4
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/kanboard/kanboard/issues/5829
Patch patch
Patch Commit
https://github.com/kanboard/kanboard/commit/928c68aa2b7c00092dd71084d329b912e229f3d1
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/kanboard-cross-user-deletion-of-persistent-login-sessions-via-unvalidated-session-id
Scores
CVSS v3
5.4
EPSS
0.0027
EPSS Percentile
18.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (2)
kanboard/kanboard
< 1.2.52
kanboard/kanboard
928c68aa2b7c00092dd71084d329b912e229f3d1
Published
Jun 25, 2026
Tracked Since
Jun 26, 2026