PT-2026-6924 · Wekan · Wekan

Joshua Rogers

·

Published

2026-02-07

·

Updated

2026-02-08

·

CVE-2026-25561

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WeKan versions prior to 8.19
Description The software contains an authorization weakness in the attachment upload API. The API does not fully validate identifiers such as boardId, cardId, swimlaneId, and listId to ensure they correctly relate to a coherent card/board relationship. This allows attempts to upload attachments with mismatched object relationships.
Recommendations Update to version 8.19 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25561

Affected Products

Wekan