Improper Restriction of Excessive Authentication Attempts in Wekan - #VU144209

 

Improper Restriction of Excessive Authentication Attempts in Wekan - #VU144209

Published: August 18, 2026


Vulnerability identifier: #VU144209
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over user accounts.

The vulnerability exists due to improper restriction of excessive authentication attempts in the wekan-accounts-lockout login protection hooks when handling password-based login failures through the DDP login method. A remote attacker can send repeated password-guessing requests to take over user accounts.

The issue depends on Meteor replacing granular login failure reasons with the generic \"Login forbidden\" response, which prevents the failure counter from incrementing and leaves the built-in lockout inactive.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 10.59

External References

Related Security Bulletins