PT-2026-78234 · 4Gaboards · 4Gaboards
CVE-2026-50191
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
4gaBoards versions prior to 3.3.8
Description
An issue exists when
registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The 'POST /api/register' endpoint allows the creation of an unverified local account using a victim's email address, and the 'POST /api/access-tokens' endpoint allows this account to authenticate even while isVerified is false. When the victim performs their first SSO login, the system links the verified SSO identity to the attacker-controlled account based on the email address without confirming ownership of the local account. This occurs within the following functions: get-create-one-for-github-sso.js(), get-create-one-for-google-sso.js(), get-create-one-for-microsoft-sso.js(), and get-create-one-for-oidc-sso.js(). Consequently, the attacker maintains local password access to the account, gaining access to the victim's projects, data, and permissions.Recommendations
Update to version 3.3.8.
Exploit
Fix
Improper Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
4Gaboards