CVE-2026-25773

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reordering categories. An attacker can inject a malicious SQL payload into the category id field, which is stored in the database and later executed unsanitized when the category reorder API processes the stored value. This Second-Order SQL Injection (Time-Based Blind) allows an authenticated attacker to exfiltrate sensitive data including password hashes of other users. NOTE: Focalboard as a standalone product is not maintained and no fix will be issued.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:focalboard:8.0.0:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) NO COMPATIBLE CUANDO SE ASIGNA Focalboard versión 8.0 no logra sanear los IDs de categoría antes de incorporarlos en sentencias SQL dinámicas al reordenar categorías. Un atacante puede inyectar una carga útil SQL maliciosa en el campo de ID de categoría, que se almacena en la base de datos y luego se ejecuta sin sanear cuando la API de reordenación de categorías procesa el valor almacenado. Esta inyección SQL de segundo orden (ciega basada en tiempo) permite a un atacante autenticado exfiltrar datos sensibles, incluyendo hashes de contraseñas de otros usuarios. NOTA: Focalboard como producto independiente no recibe mantenimiento y no se emitirá ninguna corrección.

28 Apr 2026, 00:19

Type Values Removed Values Added
References () https://github.com/mattermost-community/focalboard - () https://github.com/mattermost-community/focalboard - Product
CPE cpe:2.3:a:mattermost:focalboard:8.0.0:*:*:*:*:*:*:*
First Time Mattermost
Mattermost focalboard

03 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 14:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-25773

Mitre link : CVE-2026-25773

CVE.ORG link : CVE-2026-25773


JSON object : View

Products Affected

mattermost

  • focalboard
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')