Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53959— 4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user

CVSS 6.5 · Medium EPSS 0.03% · P11
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-53959

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user
Source: CVE Program / CVE List V5
Vulnerability Description
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The users/index and users/show actions rely only on the default is-authenticated policy in server/config/policies.js, and server/api/controllers/users/index.js returns the result of sails.helpers.users.getMany() without requester-specific authorization or response sanitization. Responses expose email, phone, organization, name, isAdmin, ssoGoogleEmail, ssoGithubEmail, and other SSO-linked email fields, including data for administrators. This enables instance-wide user enumeration, privacy loss, and targeted phishing reconnaissance. This issue is fixed in version 3.3.9.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
RARgames4gaBoards < 3.3.9 -

II. Public POCs for CVE-2026-53959

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53959

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53959 (1)

Exploits & Public PoCs for CVE-2026-53959 (1)

Same Patch Batch · RARgames · 2026-08-18 · 4 CVEs total

CVE-2026-501918.8 HIGH4gaBoards: Pre-Account Takeover via SSO Email Linkage
CVE-2026-501868.8 HIGH4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export
CVE-2026-539587.6 HIGH4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment

IV. Related Vulnerabilities

V. Comments for CVE-2026-53959

No comments yet


Leave a comment