PT-2026-6073 · Wekan · Wekan
Joshua Rogers
+2
·
Publicado
2026-02-04
·
Atualizado
2026-02-05
·
CVE-2026-1894
CVSS v3.1
6.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Wekan versions up to 8.20
Description
A security issue exists in Wekan’s REST API component, specifically within the file
models/checklistItems.js. Manipulation of the arguments item.cardId, item.checklistId, and card.boardId can lead to improper authorization. Remote exploitation is possible.Recommendations
Upgrade to version 8.21.
Correção
Improper Authorization
Incorrect Privilege Assignment
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wekan