PT-2026-6633 · Wekan · Wekan
Megamansec
·
Published
2026-02-05
·
Updated
2026-02-06
·
CVE-2026-1964
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WeKan versions prior to 8.21
Description
A flaw exists in WeKan up to version 8.20 related to improper access controls within the REST Endpoint component. The issue resides in an unknown function of the
models/boards.js file. Remote exploitation is possible.Recommendations
Upgrade to version 8.21 to resolve the issue.
Fix
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wekan