Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-39912

v2board / Xboard Authentication Token Exposure via loginWithMailLink
Back to all
CVE

CVE-2026-39912

v2board / Xboard Authentication Token Exposure via loginWithMailLink

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the loginwithmaillinkenable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/cedar2025/Xboard/blob/1fe6531924cc1ec662a88b9ef725afcf78d660bc/app/Http/Controllers/V1/Passport/AuthController.php#L51, https://github.com/cedar2025/Xboard/blob/1fe6531924cc1ec662a88b9ef725afcf78d660bc/app/Services/Auth/MailLinkService.php#L49, https://github.com/v2board/v2board/blob/0ca47622a50116d0ddd7ffb316b157afb57d25e8/app/Http/Controllers/Passport/AuthController.php#L71, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39912.json, https://nvd.nist.gov/vuln/detail/CVE-2026-39912, https://www.vulncheck.com/advisories/v2board-xboard-authentication-token-exposure-via-loginwithmaillink, https://github.com/cedar2025/Xboard/pull/873, https://github.com/v2board/v2board/pull/981, https://github.com/cedar2025/Xboard/commit/121511523f04882ec0c7447acd9b8ebcb8a47957, https://github.com/cedar2025/Xboard, https://github.com/v2board/v2board, https://chocapikk.com/posts/2026/xboard-v2board-account-takeover/

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00584%
EPSS Percentile
0.45464%
Introduced Version
0,1a0b09edd248ab5608df96d1f0da6fc7019cda50
Fix Available
121511523f04882ec0c7447acd9b8ebcb8a47957,0ca47622a50116d0ddd7ffb316b157afb57d25e8

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading