PT-2026-34568 · Wekan · Wekan

·

CVE-2026-41454

·

Published

2026-04-22

·

Updated

2026-04-23

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WeKan versions prior to 8.35
Description Insufficient authorization checks in the JsonRoutes REST handlers of the Integration REST API endpoints allow authenticated board members to perform administrative actions without proper privilege verification. This allows for the enumeration of integrations, including webhook URLs, as well as the creation, modification, or deletion of integrations and the management of integration activities.
Recommendations Update to version 8.35 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41454

Affected Products

Wekan