PT-2026-78234 · 4Gaboards · 4Gaboards

CVE-2026-50191

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 4gaBoards versions prior to 3.3.8
Description An issue exists when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The 'POST /api/register' endpoint allows the creation of an unverified local account using a victim's email address, and the 'POST /api/access-tokens' endpoint allows this account to authenticate even while isVerified is false. When the victim performs their first SSO login, the system links the verified SSO identity to the attacker-controlled account based on the email address without confirming ownership of the local account. This occurs within the following functions: get-create-one-for-github-sso.js(), get-create-one-for-google-sso.js(), get-create-one-for-microsoft-sso.js(), and get-create-one-for-oidc-sso.js(). Consequently, the attacker maintains local password access to the account, gaining access to the victim's projects, data, and permissions.
Recommendations Update to version 3.3.8.

Exploit

Fix

Improper Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50191
GHSA-F3P6-CHC6-PC77

Affected Products

4Gaboards