4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The users/index and users/show actions rely only on the default is-authenticated policy in server/config/policies.js, and server/api/controllers/users/index.js returns the result of sails.helpers.users.getMany() without requester-specific authorization or response sanitization. Responses expose email, phone, organization, name, isAdmin, ssoGoogleEmail, ssoGithubEmail, and other SSO-linked email fields, including data for administrators. This enables instance-wide user enumeration, privacy loss, and targeted phishing reconnaissance. This issue is fixed in version 3.3.9.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-53959 affecting 4gaBoards before 3.3.9. The repo contains four files: a MIT LICENSE, a README with vulnerability details and usage instructions, requirements.txt pinning requests==2.32.5, and the main exploit script exploit.py. The exploit is not part of a larger framework. The exploit workflow is simple and operational: it accepts a target base URL as a command-line argument, sends a POST request to /api/register with hardcoded credentials to create a new account, parses the returned token from the JSON response field item, and then sends an authenticated GET request to /api/users using a Bearer token. If successful, it prints the returned items array, which the README indicates may include sensitive fields such as email, phone, organization, isAdmin, and multiple SSO-linked email attributes for all users, including administrators. Structurally, exploit.py has three functions: register_user(), which performs account creation and token extraction; enum_users(), which performs the unauthorized user enumeration; and main(), which handles argument parsing and orchestrates the attack flow. There is no support for arbitrary account lookup by /api/users/:id in the code, although the README notes that as part of the vulnerability. There is also no stealth, persistence, privilege escalation, or remote code execution payload; the capability is limited to authenticated information disclosure via web API abuse. Because it includes a working exploitation sequence with a hardcoded registration payload and token reuse, it is best classified as OPERATIONAL rather than a mere detection script or README-only PoC.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.