PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58660 kanboard CVE debrief

CVE-2026-58660 is a high-severity vulnerability in Kanboard, a project management software, that allows authenticated users to move tasks from private projects they are not a member of. This issue arises from a missing ownership check in the BoardAjaxController save() method, which is used by the kanban board drag-and-drop endpoint. The vulnerability has a CVSS score of 7.2 and was fixed in commit 564cc30.

Vendor
kanboard
Product
Unknown
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-15
Original CVE updated
2026-10-08
Advisory published
2026-07-15
Advisory updated
2026-10-08

Who should care

Kanboard administrators and users who manage multiple projects with different memberships should assess their exposure to this vulnerability and prioritize verification of their instances.

Why it matters

CVE-2026-58660 is a high-severity vulnerability in Kanboard that allows authenticated users to move tasks from private projects they are not a member of, potentially disrupting project workflows and impacting project management.

  • Authenticated users can move tasks from private projects they are not a member of, potentially disrupting project workflows.
  • Task identifiers are sequential integers shared across the entire instance, allowing for task enumeration across projects.
  • The vulnerability allows for the corruption or hiding of tasks in private projects, impacting project management and tracking.
  • Verification of instance exposure and patch application is necessary to prevent exploitation.

Technical summary

The BoardAjaxController save() method in Kanboard does not verify that the supplied task_id belongs to the project_id provided by the caller. This allows any authenticated user who is a member of at least one project to enumerate and move tasks belonging to any other project on the same instance, including private projects they have no membership or role on. The vulnerability has a CVSS score of 7.2 and was fixed in commit 564cc30. Affected Kanboard instances should be verified for exposure, and administrators should prioritize patch application to prevent task enumeration and unauthorized modifications across projects.

Defensive priority

Kanboard administrators and users should assess exposure and prioritize verification of their instances, especially if they have multiple projects with different memberships.

Recommended defensive actions

  • Verify Kanboard instance exposure by checking if the installed version is less than 1.2.52.
  • Apply the patch from commit 564cc30 to fix the vulnerability.
  • Restrict drag-and-drop functionality to users with project membership.
  • Monitor for suspicious task movements on the kanban board.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details about the vulnerability, its impact, and the fix. However, the exact scope of affected versions and instances requires verification from the official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58660 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58660

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58660 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58660

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58660.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/kanboard/kanboard/issues/5852

    Supplemental source - technical-description, exploit

  • Source reference

    Unverified legacy reference

    URL: https://github.com/kanboard/kanboard/pull/5853

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/kanboard/kanboard/commit/564cc30e1e360959572e01e158734d9475c05903

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/kanboard-boardajaxcontroller-missing-ownership-check-via-drag-and-drop

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.