CVE-2026-25531 | Kanboard up to 1.2.49 Incomplete Fix CVE-2023-33968 duplicateProjects authorization (GHSA-vrm3-3337-whp9)
A vulnerability has been found in Kanboard up to 1.2.49 and classified as problematic. The affected element is the function TaskCreationController::duplicateProjects of the component Incomplete Fix CVE-2023-33968. This manipulation causes missing authorization.
This vulnerability is handled as CVE-2026-25531. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.