Missing Authorization in Wekan - #VU144212
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the board publication ancestor card handling when processing cross-board parentId relationships. A remote user can set a card\'s parentId to a card on another board to disclose sensitive information.
Exploitation requires write access on the child board and knowledge of a card identifier from another board.