Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 13 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cedar2025
Cedar2025 xboard V2board V2board v2board |
|
| Vendors & Products |
Cedar2025
Cedar2025 xboard V2board V2board v2board |
Thu, 09 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges. | |
| Title | v2board / Xboard Authentication Token Exposure via loginWithMailLink | |
| Weaknesses | CWE-201 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-13T15:38:46.529Z
Reserved: 2026-04-07T20:57:06.209Z
Link: CVE-2026-39912
Updated: 2026-04-10T20:17:22.820Z
Status : Deferred
Published: 2026-04-09T19:16:25.920
Modified: 2026-04-15T15:00:32.790
Link: CVE-2026-39912
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:31:43Z