Authorization bypass through user-controlled key in Wekan - #VU144214
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information from arbitrary private board cards and attachment bytes.
The vulnerability exists due to authorization bypass through user-controlled key in the single-card Excel export endpoint when handling requests with an authorized board identifier and an unrelated card identifier. A remote user can send a specially crafted request to disclose sensitive information from arbitrary private board cards and attachment bytes.
The list identifier is not used in the data query, and a known card identifier is required.