PT-2026-23745 · Wekan+1 · Wekan
Xet7
·
Published
2026-03-06
·
Updated
2026-03-11
·
CVE-2026-30845
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wekan versions 8.31.0 through 8.33
Description
Wekan is an open source kanban tool. In affected versions, the board composite publication publishes all integration data for a board without field filtering, exposing sensitive information like webhook URLs and authentication tokens to any subscriber. Board publications are accessible to all board members, regardless of their role, and even to unauthenticated DDP clients for public boards. This allows any user with board access to retrieve webhook credentials. This token leak enables attackers to make unauthenticated requests to exposed webhooks, potentially triggering unauthorized actions in connected external services. The issue involves the publication of sensitive data without proper access controls.
Recommendations
Upgrade to version 8.34 or later to address this issue.
Exploit
Fix
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wekan