CVE-2026-32255Disclosure(kan / kan)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch() server-side, and returns the full response body. An unauthenticated attacker can use this to make HTTP requests from the server to internal services, cloud metadata endpoints, or private network resources. This issue has been fixed in version 0.5.5. To workaround this issue, block or restrict access to /api/download/attatchment at the reverse proxy level (nginx, Cloudflare, etc.).

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kan

Threat summary

  • Public PoC is present in monitored signal
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-19); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
kan

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-19: 4Mentions · 2026-03-21: 2Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-19: 1Technical Details · 2026-03-19: 4Technical Details · 2026-03-21: 2Technical Details · 2026-08-19: 103-1903-2108-19
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-194
Disclosure4
2026-03-212
Disclosure1General1
2026-08-191
Disclosure1
Full discourse7 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-32255 - high 🚨 Kan <= 0.5.4 - Server-Side Request Forgery > Kan, an open-source project management tool (Trello alternative), versions 0.5.4 and ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-32255 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2026‑32255 is disclosed as a high‑severity Server‑Side Request Forgery affecting Kan ≤0.5.4, with a link to a Project Discovery library that may contain PoC or detection templates.

    00001220
    1.2K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-32255: Server-Side Request Forgery in Kan Project Tool - What It Means for Your Business and How to Respond https://hubs.li/Q047P-5G0

    Post summary

    The article identifies CVE‑2026‑32255 as a Server‑Side Request Forgery in Kan Project Tool and offers general business guidance, but it does not provide PoC, exploit code, active exploitation evidence, or specific patch information.

    0000018
    29 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-32255 📊 Severity: 8.6 🚨 Risk Level: High 🧩 Affects: Nginx Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32255 #CVE-2026-32255 #CVE #High #Nginx #CyberSecurity #InfoSec https://t.co/cvT8HAMGw9

    Post summary

    The tweet announces a new high‑severity CVE (CVE‑2026‑32255) affecting Nginx, providing basic severity information but offering no details on PoC, exploitation, patches, or debunking.

    0000036
    108 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Top cybersecurity news: CVE-2026-32255: Kan project management tool versions 0.5.4 and below are vulnerable to unauthenticated SSRF via the attachment download endpoint, posing significant security risks. CVE-2026-32805: Romeo's archive sanitization process is susceptible to path traversal due to missing checks, potentially allowing unauthorized access. CVE-2025-55040: MuraCMS faces a CSRF vulnerability, enabling attackers to upload malicious form definitions without user consent. CVE-2026-32000: OpenClaw versions before 2026.2.19 are vulnerable to command injection via the Lobster tool, exposing systems to potential shell metacharacter attacks. Stay sharp. Stay secure. #NerdieNews #CyberSecurity #InfoSec #ZeroDay #PatchTuesday

    Post summary

    The post enumerates several newly disclosed CVEs with brief technical details on the vulnerabilities, but provides no evidence of exploitation, proof‑of‑concept, or patch information.

    0000036
    49 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32255 Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The At… https://www.cve.org/CVERecord?id=CVE-2026-32255

    Post summary

    The passage announces CVE-2026-32255 affecting Kan with an unauthenticated download endpoint, providing technical vulnerability details but no exploit, patch, or exploitation evidence.

    00000126
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32255: HIGH] Open-source project management tool, Kan, had a major security vulnerability in versions 0.5.4 and below, allowing unauthenticated attackers to make HTTP requests to internal services....#cve,CVE-2026-32255,#cybersecurity https://cvefind.com/CVE-2026-32255

    Post summary

    The text announces a high‑severity vulnerability in Kan (v0.5.4 and earlier) that permits unauthenticated attackers to send HTTP requests to internal services, with no PoC, exploit, or patch details provided.

    0000063
    603 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32255 - High Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoin... https://www.thehackerwire.com/vulnerability/CVE-2026-32255/ https://t.co/fWyz2QwL2x

    Post summary

    The post discloses that Kan version 0.5.4 and earlier expose an unauthenticated attachment download endpoint lacking URL validation, but provides no patch, exploit code, or evidence of active exploitation.

    0000052
    138 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkankan---

Explore more