SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-53959

MEDIUM · CVSS 6.5 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The 4gaBoards project management system prior to version 3.3.9 is vulnerable, allowing authenticated users to enumerate account information and access arbitrary user data via specific API endpoints. This flaw can lead to significant privacy breaches, exposing sensitive information such as emails and phone numbers, which could facilitate targeted phishing attacks. Organizations using 4gaBoards should prioritize updating to version 3.3.9 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53959
Severity
MEDIUM
CVSS
6.5
EPSS
0.41%
GitHub

Original NVD Description

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The users/index and users/show actions rely only on the default is-authenticated policy in server/config/policies.js, and server/api/controllers/users/index.js returns the result of sails.helpers.users.getMany() without requester-specific authorization or response sanitization. Responses expose email, phone, organization, name, isAdmin, ssoGoogleEmail, ssoGithubEmail, and other SSO-linked email fields, including data for administrators. This enables instance-wide user enumeration, privacy loss, and targeted phishing reconnaissance. This issue is fixed in version 3.3.9.