PT-2026-6073 · Wekan · Wekan
Joshua Rogers
+2
·
Published
2026-02-04
·
Updated
2026-02-05
·
CVE-2026-1894
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Wekan versions up to 8.20
Description
A security issue exists in Wekan’s REST API component, specifically within the file
models/checklistItems.js. Manipulation of the arguments item.cardId, item.checklistId, and card.boardId can lead to improper authorization. Remote exploitation is possible.Recommendations
Upgrade to version 8.21.
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wekan