Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kanboard
Kanboard kanboard |
|
| Vendors & Products |
Kanboard
Kanboard kanboard |
Thu, 08 Jan 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49. | |
| Title | Kanboard LDAP Injection Vulnerability can Lead to User Enumeration and Information Disclosure | |
| Weaknesses | CWE-200 CWE-90 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-08T18:29:16.406Z
Reserved: 2026-01-05T17:24:36.928Z
Link: CVE-2026-21880
Updated: 2026-01-08T18:28:57.981Z
Status : Undergoing Analysis
Published: 2026-01-08T02:15:53.650
Modified: 2026-01-08T19:15:59.383
Link: CVE-2026-21880
No data.
OpenCVE Enrichment
Updated: 2026-01-08T09:47:41Z