PT-2026-34568 · Wekan · Wekan

Rodolphe Ghio

+1

·

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-41454

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions WeKan versions prior to 8.35
Description Insufficient authorization checks in the JsonRoutes REST handlers of the Integration REST API endpoints allow authenticated board members to perform administrative actions without proper privilege verification. This allows for the enumeration of integrations, including webhook URLs, as well as the creation, modification, or deletion of integrations and the management of integration activities.
Recommendations Update to version 8.35 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41454

Affected Products

Wekan