Incorrect authorization in Wekan - CVE-2026-59154
Published: July 28, 2026
Wekan
Detailed vulnerability description
The vulnerability allows a remote user to modify checklist data in a private board.
The vulnerability exists due to incorrect authorization in the Checklists and ChecklistItems direct DDP update rules when processing direct collection updates that change a checklist or checklist item's destination card or board. A remote user can send a specially crafted DDP update to modify checklist data in a private board.
Exploitation requires write access to a source board and knowledge of a target private card id. No membership in the target private board is required.