CVE-2026-28736 describes a medium-severity vulnerability in Focalboard version 8.0, where the application fails to validate file ownership for uploaded files. This flaw allows an authenticated attacker, with knowledge of a file's ID, to read its contents, resulting in a low impact on confidentiality with low attack complexity. The attack can be performed over the network without user interaction. There is currently no evidence of active exploitation, nor are public exploit tools or community discussions available. It is important to note that Focalboard as a standalone product is unmaintained, and no patch will be issued for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0CPE matchmatch criteria | cpe:2.3:a:mattermost:focalboard:8.0.0:*:*:*:*:*:*:* | ||
>= 0, <= 8.0CPE match | cpe:2.3:a:mattermost:focalboard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.