CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-39912

Critical · CVSS 9.1

V2Board / Xboard — Authentication token exposure in HTTP response body (CWE-201) leading to account takeover

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-201

Description

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges.

Search profile — drives PoC discovery

Symbols loginWithMailLinklogin_with_mail_link_enabletoken2LoginMailLinkServiceAuthControllerAuthController.phpMailLinkService.php
Keywords CVE-2026-39912V2BoardXboardloginWithMailLinktoken2LoginMailLinkServiceaccount takeoverauthentication token exposuremail link loginbearer tokenlogin_with_mail_link_enablepassport authxboard account takeover poc
Versions: V2Board 1.6.1–1.7.4; Xboard through 0.1.9

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z