Junglewise Threat Intelligence

CVE-2026-39912: V2Board and Xboard authentication token exposure in loginWithMailLink

CVE-2026-39912 · Severity: critical · CVSS 9.1 · Published 2026-04-09

Technologies: V2board. Vendors: V2board.

Executive brief

V2Board and Xboard, popular management panels for VPN and proxy services, contain a critical flaw in their passwordless login feature. When a user requests a login link via email, the system accidentally includes the secret authentication token in the immediate web response. An attacker can use this to gain full access to any account, including administrator accounts, knowing only the user's email address. This allows for complete takeover of the service, exposure of customer payment history, and access to private VPN server configurations.

Technical details

An information disclosure vulnerability exists in the 'loginWithMailLink' endpoint of V2Board and Xboard when the 'login_with_mail_link_enable' feature is active. The application incorrectly returns the generated magic login link (containing a sensitive 'verify' token) in the HTTP response body instead of only sending it via email. An unauthenticated attacker can trigger this by sending a POST request with a target email address, extract the token from the response, and exchange it at the 'token2Login' endpoint to obtain a valid bearer token. This results in full account takeover, including administrative privileges if the target email belongs to an admin. A patch is available for Xboard in version 0.2.0 (commit 1215115), while V2Board is reportedly abandoned and remains vulnerable.

Affected products

  • V2Board V2Board 1.6.1 through 1.7.4
  • cedar2025 Xboard through 0.1.9

Timeline

  • 2022-06-27: other: Vulnerability introduced in V2Board 1.6.1
  • 2026-04-08: disclosed: Public disclosure by security researcher Chocapikk
  • 2026-04-09: advisory: CVE-2026-39912 published
  • 2026-04-09: patched: Xboard fix committed to main branch

References

Related threats