PT-2026-6928 · Wekan · Wekan
Joshua Rogers
·
Published
2026-02-07
·
Updated
2026-02-08
·
CVE-2026-25565
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
WeKan versions prior to 8.19
Description
WeKan contains an authorization issue in certain card update API paths. These paths only validate read access to a board instead of requiring write permission. This allows users with read-only roles to perform card updates that should require write access. The affected API paths are not explicitly named, but involve card updates.
Recommendations
Update WeKan to version 8.19 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wekan