CVE-2026-41418 | RARgames 4gaBoards up to 3.3.4 Login Endpoint /api/access-tokens bcrypt.compareSync timing discrepancy (GHSA-8mj9-p99h-jhxp)
A vulnerability classified as problematic has been found in RARgames 4gaBoards up to 3.3.4. This impacts the function bcrypt.compareSync of the file /api/access-tokens of the component Login Endpoint. This manipulation causes observable timing discrepancy.
This vulnerability appears as CVE-2026-41418. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.