Junglewise Threat Intelligence

CVE-2026-25773: Mattermost Focalboard SQL injection in category reorder API

CVE-2026-25773 · Severity: high · CVSS 8.1 · Published 2026-04-03

Vendors: Go, Mattermost.

Executive brief

Focalboard is an open-source project management tool used as an alternative to Trello and Notion. A security flaw allows an authenticated user to perform a database attack that can lead to the theft of sensitive information, including the password hashes of other users. Because this standalone version of the product is no longer maintained, no official security patch will be released to fix this issue.

Technical details

A second-order (time-based blind) SQL injection vulnerability exists in Focalboard version 8.0. The application fails to sanitize category IDs before they are stored in the database and subsequently used in dynamic SQL statements within the category reorder API. An authenticated attacker can submit a malicious SQL payload in the category ID field; when the reorder API later processes this stored value, the payload is executed. This allows for the exfiltration of sensitive data, such as user password hashes. As the standalone product is end-of-life, no fix is available.

Affected products

  • Mattermost Focalboard 8.0 and earlier

Timeline

  • 2026-04-03: advisory: Vulnerability disclosed as unsupported when assigned

References

Related threats