ID:12257 - Exploit for LDAP injection in Kanboard - CVE-2026-21880
Published: January 7, 2026
Kanboard
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper input validation within LDAP authentication mechanism. A remote attacker can send a specially crafted LDAP query to the application, bypass authentication process and gain unauthorized access to sensitive information on the system.