PatchSiren

RARgames CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM RARgames CVE published 2026-08-18

CVE-2026-53959

The 4gaBoards system for realtime project management, prior to version 3.3.9, allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The vulnerability exists due to insufficient authorization and response sanitization in the users/index and users/show actions. This enables instance-wide user enumerati [truncated]

HIGH RARgames CVE published 2026-08-18

CVE-2026-53958

CVE-2026-53958 is a vulnerability in 4gaBoards, a boards system for real-time project management. An authenticated user can modify certain backend-managed identity attributes through PATCH /api/users/:id, allowing an attacker to place a victim's provider identifier on an attacker-controlled account. This causes the default lookup to match the victim's first SSO login to the attacker's account before the e [truncated]

HIGH RARgames CVE published 2026-08-18

CVE-2026-50191

CVE-2026-50191 is a high-severity vulnerability in 4gaBoards, a real-time project management system. The issue allows for pre-account takeover when certain configurations are enabled, permitting an attacker to create an unverified local account with a victim's email address and link it to a verified SSO identity without confirming ownership. This could lead to unauthorized access to the victim's projects, [truncated]