CVE-2026-39912Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-201

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 6 mentions (2026-04-09); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-04-09: 6Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 5Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 104-0904-1104-12
Signal classification3 categories
Disclosure
562.5%
General
225.0%
Patch
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-096
Disclosure5Patch1
2026-04-111
General1
2026-04-121
General1
Full discourse8 posts
  • Chocapikk@Chocapikk_
    Disclosure

    CVE-2026-39912 - Unauthenticated account takeover on Xboard/V2Board. The loginWithMailLink endpoint returns the magic link in the API response. Two requests, zero credentials, full account access. https://chocapikk.com/posts/2026/xboard-v2board-account-takeover/

    Post summary

    CVE-2026-39912 is an unauthenticated account takeover flaw in Xboard/V2Board where the loginWithMailLink endpoint exposes a magic link, enabling full account access with two requests and no credentials.

    0501541.3K
    4.0K followersView on X
  • z3n@zench4n
    General

    Monitor for patterns similar to recent token leaks like CVE-2026-39912. In agentic workflows, a leaked session token via an injected response can lead to full account takeover. Security must be baked into the reasoning loop, not just the perimeter.

    Post summary

    The post warns of token leak vulnerabilities like CVE-2026-39912 that allow full account takeover, urging vigilance without providing exploits, patches, or proof of ongoing attacks.

    0001045
    1.5K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-39912 — CVSS 9.1/10 █████████░ V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/8FILqiyCKd

    Post summary

    CVE‑2026‑39912 is a critical flaw that exposes authentication tokens in HTTP responses, and a patch is now available.

    1000063
    16 followersView on X
  • z3n@zench4n
    General

    Always audit third-party libs in your AI stack. The Xboard token leak (CVE-2026-39912) and Windows CLFS exploit (CVE-2025-60709) show how auth bypass can lead to full system compromise. Fuzz your agents' input handlers.

    Post summary

    The message highlights two CVEs involving authentication bypass and token leak that could lead to full system compromise, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000331
    1.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39912 V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_l… https://www.cve.org/CVERecord?id=CVE-2026-39912 ----- Traducción: CVE-2026-39912 V2B… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑39912, noting that authentication tokens are exposed in the loginWithMailLink response of V2Board and Xboard, but provides no exploit, patch, or detailed technical classification.

    0000053
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39912 V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_l… https://www.cve.org/CVERecord?id=CVE-2026-39912

    Post summary

    The mention details a token exposure vulnerability identified by CVE‑2026‑39912 in V2Board and Xboard, without indicating exploitation, patches, or debunking.

    00000162
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-39912: CRITICAL] V2Board and Xboard versions 1.6.1 to 1.7.4 have a security vulnerability. Attackers can obtain authentication tokens by exploiting the loginWithMailLink endpoint, granting unauthor...#cve,CVE-2026-39912,#cybersecurity https://cvefind.com/CVE-2026-39912

    Post summary

    CVE-2026-39912 is a critical flaw in V2Board/Xboard that lets attackers retrieve authentication tokens through a specific endpoint; the post offers a high‑level disclosure but no PoC, exploit, patch, or active exploitation reports.

    0000082
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39912: v2board / Xboard Authentication ... Magic link auth gone wrong - POST any email to loginWithMailLink, get back full auth URL in response body, instant admi... https://zerodaysignal.com/vulnerability/CVE-2026-39912 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑39912, detailing how v2board/Xboard’s magic link authentication can be exploited by sending any email to the loginWithMailLink endpoint, thereby leaking an authenticated URL.

    0000070
    204 followersView on X

Explore more