CVE-2026-39912 affects V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 when the passwordless "login with mail link" feature (login_with_mail_link_enable) is enabled. The loginWithMailLink endpoint improperly includes the full magic-login URL, including the verification token, in the HTTP response body after processing a request for a supplied email address. Because the endpoint is reachable without authentication, an attacker who knows a valid user email address can POST to /api/v1/passport/auth/loginWithMailLink, obtain the verify token from the returned URL, and then submit that token to /api/v1/passport/auth/token2Login to receive a valid bearer token for the victim account. The flaw is an exposure of sensitive information in an API response that directly enables authentication bypass and full account takeover, including administrator accounts if the targeted email belongs to an admin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-39912 affecting V2Board and Xboard. It contains two files: a README documenting the vulnerability, affected versions, prerequisites, and usage; and exploit.py, the actual exploit implementation. The exploit targets a logic/information disclosure flaw in the magic-link authentication flow: the unauthenticated endpoint api/v1/passport/auth/loginWithMailLink returns the full login link in the HTTP response body instead of only emailing it to the user. The script posts a known victim email to that endpoint, extracts the verify token from the leaked link, exchanges it at api/v1/passport/auth/token2Login for auth_data, stores the returned bearer token, and then queries a hardcoded list of authenticated API endpoints to dump available account data. The code is operational rather than framework-based: it uses requests.Session, argparse, regex token extraction, and optional JSON file output. Main capabilities are unauthenticated account takeover of any registered user when mail-link login is enabled, privilege inheritance including possible admin access, and broad post-authentication data collection from user-related API routes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication token exposure vulnerability in V2Board and Xboard that allows unauthenticated attackers to obtain a valid bearer token and take over accounts, including admin accounts, via the loginWithMailLink and token2Login endpoints.
An account takeover vulnerability in V2Board and Xboard where the passwordless 'login with mail link' feature returns the secret magic login URL in the API response, allowing unauthenticated attackers with a valid email address to obtain a fully authenticated session, including admin access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.