CVE-2023-39691: Kodcloud Kodbox

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.

Affected products

  • Kodcloud Kodbox: up to and including 1.43

Published 2024-01-16. Last modified 2026-06-17.