CRITICAL🇵🇱 Wersja polska

CVE-2026-30843

CVSS 9.3v4.0pub. 2026-03-06upd. 2026-03-11

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which could allow unauthorized users to modify custom fields across boards through its custom fields update endpoints, potentially leading to unauthorized data manipulation. The PUT /api/boards/:boardId/custom-fields/:customFieldId endpoint in Wekan validates that the authenticated user has access to the specified boardId, but the subsequent database update uses only the custom field's _id as a filter without confirming the field actually belongs to that board. This means an attacker who owns any board can modify custom fields on any other board by supplying a foreign custom field ID, and the same flaw exists in the POST, PUT, and DELETE endpoints for dropdown items under custom fields. The required custom field IDs can be obtained by exporting a board (which only needs read access), since the exported JSON includes the IDs of all board components. The authorization check is performed against the wrong resource, allowing cross-board custom field manipulation. This issue has been fixed in version 8.34.

🤖 AI Analysis
How it works

The PUT /api/boards/:boardId/custom-fields/:customFieldId endpoint verifies whether the user has access to the provided boardId, however the subsequent database update operation filters records only by custom field identifier (_id), without checking whether the field actually belongs to the indicated board. An attacker possessing their own board can therefore specify the custom field identifier from another board and modify it without permissions. The same flaw affects POST, PUT and DELETE endpoints for dropdown items associated with custom fields. Custom field identifiers from other boards can be obtained by exporting a board to which the attacker has read-only access, since the exported JSON file contains identifiers of all board components.

Impact

An attacker can unauthorized modify or delete custom fields and their values on any boards in a Wekan instance, leading to manipulation of project data of other users and teams.

Mitigation & patch

Wekan should be updated to version 8.34, in which the manufacturer removed the described vulnerability. The patch is available in the project's GitHub repository (commit 73eb98c57afd3d72377a1f7160a52450ab0eeb8b) and as part of the v8.34 release.

Who is affected

Wekan Project Wekan in versions 8.32 and 8.33

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Wekan Project Wekan

    APP
    Wekan Project
    8.328.33
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
IDOR
CWE
References

Related vulnerabilities

CVE-2026-30844CRITICAL9.3PL ✓same product

SSRF w Wekan — nieautoryzowany dostęp do wewnętrznych zasobów sieciowych

CVE-2026-30847CRITICAL9.3PL ✓same product

Wekan: ujawnienie wrażliwych danych użytkowników przez publikację notificationUsers

CVE-2026-30846HIGH8.7same product

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks pub...

CVE-2026-25564HIGH7.1same product

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and rela...

CVE-2026-25561HIGH7.1same product

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not ...