Vulnerability Description
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in server/api/controllers/users/update.js mass assigns these backend-managed identity attributes from user input. An attacker can place a victim's provider identifier on an attacker-controlled account, causing the default lookup in helpers such as server/api/helpers/users/get-create-one-for-github-sso.js to match the victim's first SSO login to the attacker's account before the email-linkage flow runs. The victim is logged into the attacker-controlled account, and projects, boards, or data the victim creates remain accessible through the attacker's original local credentials. This issue is fixed in version 3.3.9.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/RARgames/4gaBoards/commit/7a79f4c5d338614058515752abd67e49ee2
- https://github.com/RARgames/4gaBoards/releases/tag/v3.3.9
- https://github.com/RARgames/4gaBoards/security/advisories/GHSA-j2fw-r2gj-hfr3
- https://github.com/RARgames/4gaBoards/security/advisories/GHSA-j2fw-r2gj-hfr3
FAQ
What is CVE-2026-53958?
CVE-2026-53958 is a vulnerability with a CVSS score of 7.6 (HIGH). 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEma...
How severe is CVE-2026-53958?
CVE-2026-53958 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53958?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.