WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XWekan Project Wekan
APPWekan Project< 8.19
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
IDOR
CWE
Related vulnerabilities
CVE-2026-30844CRITICAL9.3PL ✓same product
SSRF w Wekan — nieautoryzowany dostęp do wewnętrznych zasobów sieciowych
CVE-2026-30847CRITICAL9.3PL ✓same product
Wekan: ujawnienie wrażliwych danych użytkowników przez publikację notificationUsers
CVE-2026-30843CRITICAL9.3PL ✓same product
Wekan IDOR: nieautoryzowana modyfikacja pól własnych na tablicach
CVE-2026-30846HIGH8.7same product
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks pub...
CVE-2026-25565HIGH7.1same product
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths valida...