PT-2026-78240 · 4Gaboards · 4Gaboards
CVE-2026-53958
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
4gaBoards versions prior to 3.3.9
Description
An authenticated user can modify backend-managed identity attributes via the 'PATCH /api/users/:id' endpoint. This occurs because the whitelist in the
update.js controller allows mass assignment of variables including ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail. An attacker can assign a victim's provider identifier to an account they control. Consequently, when the victim performs their first SSO login, the system matches them to the attacker's account. This results in the victim being logged into the attacker-controlled account, allowing the attacker to access any projects, boards, or data the victim subsequently creates using the attacker's original local credentials.Recommendations
Update to version 3.3.9.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
4Gaboards