PT-2026-6076 · Wekan · Wekan

·

CVE-2026-1897

·

Published

2026-02-05

·

Updated

2026-02-05

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions WeKan versions prior to 8.21
Description A flaw exists in WeKan related to missing authorization within the Position-History Tracking component, specifically in the file server/methods/positionHistory.js. This issue allows for remote manipulation, potentially leading to unauthorized access.
Recommendations Upgrade to version 8.21 or later to resolve this issue.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1897

Affected Products

Wekan