CVE-2026-33058Disclosure(kanboard / kanboard)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the entirety of the kanboard database. Version 1.2.51 fixes the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kanboard

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
kanboard

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-19: 2PoC Mentioned / Linked · 2026-03-19: 1Technical Details · 2026-03-18: 3Technical Details · 2026-03-19: 103-1803-19
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure2General1
2026-03-192
Disclosure1PoC1
Full discourse5 posts
  • /r/netsec@_r_netsec
    PoC

    Kanboard Authenticated SQL Injection CVE-2026-33058 Writeup https://0dave.ch/posts/cve-2026-33058/

    Post summary

    The post links to a writeup for CVE‑2026‑33058, an authenticated SQL injection in Kanboard, suggesting the availability of a PoC, but no active exploitation, patch info, or detailed technical data is present.

    03032516
    32.9K followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    Kanboard Authenticated SQL Injection CVE-2026-33058 Writeup https://0dave.ch/posts/cve-2026-33058/ https://t.co/dM1F9O16JD

    Post summary

    The text announces a writeup describing the authenticated SQL injection vulnerability CVE-2026-33058 in Kanboard, detailing the exploit type but not providing PoC, exploit code, patch information, or evidence of active exploitation.

    0000099
    793 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33058 Authenticated SQL Injection in Kanboard Prior to Version 1.2.51 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33058

    Post summary

    The post announces CVE-2026-33058, an authenticated SQL injection flaw affecting Kanboard versions earlier than 1.2.51, without providing PoC, exploit, or mitigation details.

    0000040
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33058 📊 Severity: 8.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33058 #CVE-2026-33058 #CVE #High  #CyberSecurity #InfoSec https://t.co/jhSqilePS4

    Post summary

    A new high‑severity CVE (8.4) is announced with minimal details and a link to the NVD entry.

    0000033
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33058 Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the … https://www.cve.org/CVERecord?id=CVE-2026-33058

    Post summary

    CVE-2026-33058 is an authenticated SQL injection in Kanboard versions prior to 1.2.51, with no PoC, exploit, or patch mentioned; no evidence of active exploitation.

    0000071
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkanboardkanboard---

Explore more