PT-2026-78240 · 4Gaboards · 4Gaboards

CVE-2026-53958

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions 4gaBoards versions prior to 3.3.9
Description An authenticated user can modify backend-managed identity attributes via the 'PATCH /api/users/:id' endpoint. This occurs because the whitelist in the update.js controller allows mass assignment of variables including ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail. An attacker can assign a victim's provider identifier to an account they control. Consequently, when the victim performs their first SSO login, the system matches them to the attacker's account. This results in the victim being logged into the attacker-controlled account, allowing the attacker to access any projects, boards, or data the victim subsequently creates using the attacker's original local credentials.
Recommendations Update to version 3.3.9.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53958
GHSA-J2FW-R2GJ-HFR3

Affected Products

4Gaboards