PT-2026-6947 · Wekan · Wekan

Megamansec

·

Published

2026-02-08

·

Updated

2026-02-08

·

CVE-2026-2208

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeKan versions prior to 8.21
Description A security issue exists in WeKan related to missing authorization within the Rules Handler component. The problem resides in an unknown function of the file server/publications/rules.js. This can be exploited remotely.
Recommendations Upgrade to version 8.21 to resolve the issue.

Fix

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-2208

Affected Products

Wekan