CVE-2026-29056 | Kanboard up to 1.2.50 Registration register dynamically-determined object attributes (GHSA-2jvj-q44v-6p3x / Nessus ID 302888)
A vulnerability was found in Kanboard up to 1.2.50. It has been classified as critical. The affected element is the function UserInviteController::register of the component Registration Handler. Performing a manipulation results in dynamically-determined object attributes.
This vulnerability is cataloged as CVE-2026-29056. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.