PT-2026-23745 · Wekan+1 · Wekan
Xet7
·
Publicado
2026-03-06
·
Atualizado
2026-03-11
·
CVE-2026-30845
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wekan versions 8.31.0 through 8.33
Description
Wekan is an open source kanban tool. In affected versions, the board composite publication publishes all integration data for a board without field filtering, exposing sensitive information like webhook URLs and authentication tokens to any subscriber. Board publications are accessible to all board members, regardless of their role, and even to unauthenticated DDP clients for public boards. This allows any user with board access to retrieve webhook credentials. This token leak enables attackers to make unauthenticated requests to exposed webhooks, potentially triggering unauthorized actions in connected external services. The issue involves the publication of sensitive data without proper access controls.
Recommendations
Upgrade to version 8.34 or later to address this issue.
Exploit
Correção
Missing Authorization
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wekan