Incorrect authorization in Wekan - #VU144213

 

Incorrect authorization in Wekan - #VU144213

Published: August 18, 2026


Vulnerability identifier: #VU144213
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in Meteor.publish(\'board\') in server/publications/boards.js when handling board subscription requests for a known boardId. A remote user can subscribe to a revoked org, team, or domain-shared private board to disclose sensitive information.

The issue occurs after a board share has been revoked by setting isActive to false, and users who retained the boardId can still receive the full private board payload. The same behavior applies to organization, team, and domain share arrays.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 10.74

External References

Related Security Bulletins