Junglewise Threat Intelligence

CVE-2026-81822: PIMBoards weak password hash brute-force in project files

CVE-2026-81822 · Severity: high · CVSS 8.4 · Published 2026-09-08

Executive brief

PIMBoards is a collaborative project management platform where users store files and project data. This vulnerability allows an attacker with read access to project files to crack user passwords through computational brute-forcing of inadequately hashed credentials, potentially leading to administrator account takeover and full control of the system.

Technical details

The vulnerability stems from the use of weak cryptographic hashing for PIMBoards user passwords stored within project files. An attacker with read access to project files can extract password hashes and perform efficient brute-force attacks due to insufficient hash complexity or iteration count. No authentication is required beyond file system access, making this a post-compromise privilege escalation vector. Successful exploitation enables account compromise and potential elevation to administrator privileges, granting complete system access and data exposure.

Affected products

  • PIMBoards

Timeline

  • 2026-09-08: disclosed

References

Related threats