The 4gaBoards system for realtime project management, prior to version 3.3.9, allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The vulnerability exists due to insufficient authorization and response sanitization in the users/index and users/show actions. This enables instance-wide user enumerati [truncated]
CVE-2026-53958 is a vulnerability in 4gaBoards, a boards system for real-time project management. An authenticated user can modify certain backend-managed identity attributes through PATCH /api/users/:id, allowing an attacker to place a victim's provider identifier on an attacker-controlled account. This causes the default lookup to match the victim's first SSO login to the attacker's account before the e [truncated]
CVE-2026-50191 is a high-severity vulnerability in 4gaBoards, a real-time project management system. The issue allows for pre-account takeover when certain configurations are enabled, permitting an attacker to create an unverified local account with a victim's email address and link it to a verified SSO identity without confirming ownership. This could lead to unauthorized access to the victim's projects, [truncated]