Server-Side Request Forgery (SSRF) in Wekan - CVE-2026-53446
Published: July 28, 2026
Wekan
Detailed vulnerability description
The vulnerability allows a remote user to access internal network resources and disclose sensitive information.
The vulnerability exists due to server-side request forgery in the webhook integration system when processing user-controlled webhook integration URLs. A remote user can create or update a webhook integration with a crafted URL to access internal network resources and disclose sensitive information.
Exploitation requires board admin permissions.