PatchSiren cyber security CVE debrief
CVE-2026-58660 kanboard CVE debrief
CVE-2026-58660 is a high-severity vulnerability in Kanboard, a project management software, that allows authenticated users to move tasks from private projects they are not a member of. This issue arises from a missing ownership check in the BoardAjaxController save() method, which is used by the kanban board drag-and-drop endpoint. The vulnerability has a CVSS score of 7.2 and was fixed in commit 564cc30.
- Vendor
- kanboard
- Product
- Unknown
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-15
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-07-15
- Advisory updated
- 2026-10-08
Who should care
Kanboard administrators and users who manage multiple projects with different memberships should assess their exposure to this vulnerability and prioritize verification of their instances.
Why it matters
CVE-2026-58660 is a high-severity vulnerability in Kanboard that allows authenticated users to move tasks from private projects they are not a member of, potentially disrupting project workflows and impacting project management.
- Authenticated users can move tasks from private projects they are not a member of, potentially disrupting project workflows.
- Task identifiers are sequential integers shared across the entire instance, allowing for task enumeration across projects.
- The vulnerability allows for the corruption or hiding of tasks in private projects, impacting project management and tracking.
- Verification of instance exposure and patch application is necessary to prevent exploitation.
Technical summary
The BoardAjaxController save() method in Kanboard does not verify that the supplied task_id belongs to the project_id provided by the caller. This allows any authenticated user who is a member of at least one project to enumerate and move tasks belonging to any other project on the same instance, including private projects they have no membership or role on. The vulnerability has a CVSS score of 7.2 and was fixed in commit 564cc30. Affected Kanboard instances should be verified for exposure, and administrators should prioritize patch application to prevent task enumeration and unauthorized modifications across projects.
Defensive priority
Kanboard administrators and users should assess exposure and prioritize verification of their instances, especially if they have multiple projects with different memberships.
Recommended defensive actions
- Verify Kanboard instance exposure by checking if the installed version is less than 1.2.52.
- Apply the patch from commit 564cc30 to fix the vulnerability.
- Restrict drag-and-drop functionality to users with project membership.
- Monitor for suspicious task movements on the kanban board.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details about the vulnerability, its impact, and the fix. However, the exact scope of affected versions and instances requires verification from the official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58660 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58660
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58660 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58660
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58660.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/kanboard/kanboard/issues/5852
Supplemental source - technical-description, exploit
-
Source reference
Unverified legacy reference
URL: https://github.com/kanboard/kanboard/pull/5853
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/kanboard/kanboard/commit/564cc30e1e360959572e01e158734d9475c05903
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/kanboard-boardajaxcontroller-missing-ownership-check-via-drag-and-drop
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.