SB2026081866 - Improper Neutralization of Special Elements in Data Query Logic in Wekan



SB2026081866 - Improper Neutralization of Special Elements in Data Query Logic in Wekan

Published: August 18, 2026

Security Bulletin ID SB2026081866
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: N/A)

CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper neutralization of special elements in data query logic in the Admin Panel people, org, team, and translation publications and related count methods when processing a client-supplied query selector. A remote privileged user can send a specially crafted query containing MongoDB execution operators to cause a denial of service.

The issue affects DDP-accessible Admin Panel query surfaces, and user interaction is not required. On real MongoDB deployments, injected $where expressions may be evaluated once per scanned document.


Remediation

Install update from vendor's website.