Information Exposure Through Timing Discrepancy in Wekan - #VU144208
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to enumerate valid user accounts.
The vulnerability exists due to an observable timing discrepancy in the accounts-password login flow when processing login attempts for existing and non-existing users. A remote attacker can send specially crafted login requests and measure response times to enumerate valid user accounts.
Password-based login must be enabled for exploitation of this issue.