Chocapikk[verified]@Chocapikk_Disclosure
CVE-2026-39912 is an unauthenticated account takeover flaw in Xboard/V2Board where the loginWithMailLink endpoint exposes a magic link, enabling full account access with two requests and no credentials.
z3n[verified]@zench4nGeneral
The post warns of token leak vulnerabilities like CVE-2026-39912 that allow full account takeover, urging vigilance without providing exploits, patches, or proof of ongoing attacks.
Orizon[verified]@OrizonCyberPatch
CVE‑2026‑39912 is a critical flaw that exposes authentication tokens in HTTP responses, and a patch is now available.
z3n[verified]@zench4nGeneral
The message highlights two CVEs involving authentication bypass and token leak that could lead to full system compromise, but provides no PoC, exploit code, patch, or evidence of active exploitation.
Infoflowcloud@infoflowcloudDisclosure
The text announces CVE‑2026‑39912, noting that authentication tokens are exposed in the loginWithMailLink response of V2Board and Xboard, but provides no exploit, patch, or detailed technical classification.
CVE@CVEnewDisclosure
The mention details a token exposure vulnerability identified by CVE‑2026‑39912 in V2Board and Xboard, without indicating exploitation, patches, or debunking.
CVEFind.com@CveFindComDisclosure
CVE-2026-39912 is a critical flaw in V2Board/Xboard that lets attackers retrieve authentication tokens through a specific endpoint; the post offers a high‑level disclosure but no PoC, exploit, patch, or active exploitation reports.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2026‑39912, detailing how v2board/Xboard’s magic link authentication can be exploited by sending any email to the loginWithMailLink endpoint, thereby leaking an authenticated URL.