PT-2026-6076 · Wekan · Wekan

Joshua Rogers

+2

·

Published

2026-02-05

·

Updated

2026-02-05

·

CVE-2026-1897

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeKan versions prior to 8.21
Description A flaw exists in WeKan related to missing authorization within the Position-History Tracking component, specifically in the file server/methods/positionHistory.js. This issue allows for remote manipulation, potentially leading to unauthorized access.
Recommendations Upgrade to version 8.21 or later to resolve this issue.

Fix

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1897

Affected Products

Wekan