CVE-2026-33058 is an authenticated SQL injection vulnerability (CWE-89) affecting Kanboard project management software versions prior to 1.2.51. This medium severity vulnerability (CVSS 6.5) allows an attacker with low privileges, specifically the permission to add users to a project, to remotely dump the entire Kanboard database with low attack complexity and no user interaction. While not currently listed in CISA's KEV catalog or major exploit databases, the vulnerability has garnered community attention with multiple public write-ups detailing its exploitation. Organizations using Kanboard should upgrade to version 1.2.51 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.51CPE matchmatch criteria | cpe:2.3:a:kanboard:kanboard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.