CVE-2026-41418Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). When an invalid username/email is provided, the server responds immediately (~17ms average). When a valid username/email is provided with an incorrect password, the server first performs a bcrypt.compareSync() operation (~74ms average) before responding. This ~4.4× timing difference is trivially detectable even over a network — a single request suffices. This vulnerability is fixed in 3.3.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 104-2404-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41418 User Enumeration via Timing Side-Channel in 4ga Boards Before 3.3.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41418

    Post summary

    The statement announces CVE‑2026‑41418, describing a timing side‑channel vulnerability that allows user enumeration on 4ga boards with firmware prior to 3.3.5.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41418 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login end… https://www.cve.org/CVERecord?id=CVE-2026-41418

    Post summary

    The text announces the discovery of CVE‑2026‑41418, describing a timing side‑channel that allows user enumeration in 4ga Boards before version 3.3.5, but does not provide exploitation or remediation details.

    0000083
    57.2K followersView on X

Explore more