CVE-2026-21880
published 2026-01-08CVE-2026-21880: Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.35%
27.5th percentile
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kanboard | < kanboard 1.2.49+ds-1 (forky) | kanboard 1.2.49+ds-1 (forky) |
| kanboard | kanboard | < 1.2.49 | 1.2.49 |
| kanboard | kanboard | >= 0 < 1.2.49+ds-1 | 1.2.49+ds-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2026-21880: kanboard - Kanboard is project management software focused on Kanban methodology. Versions ...
vendor_debian·2026·CVSS 5.3
CVE-2026-21880 [MEDIUM] CVE-2026-21880: kanboard - Kanboard is project management software focused on Kanban methodology. Versions ...
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
Scope: local
forky: resolved (fixed in 1.2.49+ds-1)
sid: resolved (fixed in 1.2.49+ds-1)
OSV
CVE-2026-21880: Kanboard is project management software focused on Kanban methodology
osv·2026-01-08·CVSS 5.3
CVE-2026-21880 [MEDIUM] CVE-2026-21880: Kanboard is project management software focused on Kanban methodology
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
No detection rules found.
No public exploits indexed.
2026-01-08
Published