CVE-2026-53958: CWE-287: Improper Authentication in RARgames 4gaBoards
CVE-2026-53958 is an improper authentication vulnerability in 4gaBoards prior to version 3.3.9. It allows an authenticated user to modify backend-managed single sign-on (SSO) identity attributes via a PATCH request, enabling an attacker to link a victim's SSO provider identifier to the attacker's account. This causes the victim to be logged into the attacker's account on their first SSO login, potentially exposing the victim's projects and data to the attacker. The issue is fixed in version 3.3.9.
AI Analysis
Technical Summary
4gaBoards versions before 3.3.9 have a vulnerability where authenticated users can modify SSO identity attributes (such as ssoGoogleId, ssoGithubId, ssoMicrosoftId, ssoOidcId, and associated emails) through the PATCH /api/users/:id endpoint. The server-side whitelist improperly mass assigns these backend-managed attributes from user input. An attacker can exploit this by assigning a victim's SSO provider identifier to an attacker-controlled account. When the victim logs in via SSO, the system matches the victim's login to the attacker's account before the email-linkage flow executes, resulting in the victim being logged into the attacker's account. This leads to unauthorized access to the victim's projects, boards, and data through the attacker's credentials. The vulnerability is addressed in 4gaBoards version 3.3.9.
Potential Impact
An attacker can cause a victim to be logged into the attacker's account during their first SSO login, leading to unauthorized access to the victim's projects, boards, and data. This compromises confidentiality and integrity of user data with high impact on confidentiality and integrity and low impact on availability. The CVSS v3.1 score is 7.6 (high severity) with network attack vector, low attack complexity, requiring privileges and user interaction, and resulting in high confidentiality and integrity impact.
Mitigation Recommendations
This vulnerability is fixed in 4gaBoards version 3.3.9. Users should upgrade to version 3.3.9 or later to remediate this issue. No official patch link is provided in the data, so verify the fix availability from the vendor's official channels. Since this is not a cloud service, remediation depends on user upgrade. Patch status is not explicitly confirmed beyond the fix version statement; check vendor advisory for current remediation guidance.
CVE-2026-53958: CWE-287: Improper Authentication in RARgames 4gaBoards
Description
CVE-2026-53958 is an improper authentication vulnerability in 4gaBoards prior to version 3.3.9. It allows an authenticated user to modify backend-managed single sign-on (SSO) identity attributes via a PATCH request, enabling an attacker to link a victim's SSO provider identifier to the attacker's account. This causes the victim to be logged into the attacker's account on their first SSO login, potentially exposing the victim's projects and data to the attacker. The issue is fixed in version 3.3.9.
CVSS v3.1
Score 7.6high
Affected software
pkg:github/rargames/4gaBoardsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
4gaBoards versions before 3.3.9 have a vulnerability where authenticated users can modify SSO identity attributes (such as ssoGoogleId, ssoGithubId, ssoMicrosoftId, ssoOidcId, and associated emails) through the PATCH /api/users/:id endpoint. The server-side whitelist improperly mass assigns these backend-managed attributes from user input. An attacker can exploit this by assigning a victim's SSO provider identifier to an attacker-controlled account. When the victim logs in via SSO, the system matches the victim's login to the attacker's account before the email-linkage flow executes, resulting in the victim being logged into the attacker's account. This leads to unauthorized access to the victim's projects, boards, and data through the attacker's credentials. The vulnerability is addressed in 4gaBoards version 3.3.9.
Potential Impact
An attacker can cause a victim to be logged into the attacker's account during their first SSO login, leading to unauthorized access to the victim's projects, boards, and data. This compromises confidentiality and integrity of user data with high impact on confidentiality and integrity and low impact on availability. The CVSS v3.1 score is 7.6 (high severity) with network attack vector, low attack complexity, requiring privileges and user interaction, and resulting in high confidentiality and integrity impact.
Mitigation Recommendations
This vulnerability is fixed in 4gaBoards version 3.3.9. Users should upgrade to version 3.3.9 or later to remediate this issue. No official patch link is provided in the data, so verify the fix availability from the vendor's official channels. Since this is not a cloud service, remediation depends on user upgrade. Patch status is not explicitly confirmed beyond the fix version statement; check vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-11T15:50:01.282Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a84d38cc6e8be0332cafccd
Added to database: 08/18/2026, 21:50:04 UTC
Last enriched: 08/18/2026, 22:04:22 UTC
Last updated: 08/18/2026, 22:09:20 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.