WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XWekan Project Wekan
APPWekan Project< 8.19
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2026-30844CRITICAL9.3PL ✓same product
SSRF w Wekan — nieautoryzowany dostęp do wewnętrznych zasobów sieciowych
CVE-2026-30847CRITICAL9.3PL ✓same product
Wekan: ujawnienie wrażliwych danych użytkowników przez publikację notificationUsers
CVE-2026-30843CRITICAL9.3PL ✓same product
Wekan IDOR: nieautoryzowana modyfikacja pól własnych na tablicach
CVE-2026-30846HIGH8.7same product
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks pub...
CVE-2026-25564HIGH7.1same product
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and rela...