CVE Feed

    Dashboard / CVE / CVE-2026-39912

    CVE-2026-39912

    V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges.

    Published:Apr 9, 2026
    Last Modified:Jul 14, 2026
    EPS:Apr 9, 2026
    EPSS Score:0.00584
    CVSS Score:9.1

    Affected Products

    Vendor
    Cedar2025
    Product
    Xboard
    Vendor
    V2board
    Product
    V2board

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High