PT-2026-6924 · Wekan · Wekan
Joshua Rogers
·
Published
2026-02-07
·
Updated
2026-02-08
·
CVE-2026-25561
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WeKan versions prior to 8.19
Description
The software contains an authorization weakness in the attachment upload API. The API does not fully validate identifiers such as
boardId, cardId, swimlaneId, and listId to ensure they correctly relate to a coherent card/board relationship. This allows attempts to upload attachments with mismatched object relationships.Recommendations
Update to version 8.19 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wekan