Improper Neutralization of Special Elements in Data Query Logic in Wekan - #VU144215

 

Improper Neutralization of Special Elements in Data Query Logic in Wekan - #VU144215

Published: August 18, 2026


Vulnerability identifier: #VU144215
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper neutralization of special elements in data query logic in the Admin Panel people, org, team, and translation publications and related count methods when processing a client-supplied query selector. A remote privileged user can send a specially crafted query containing MongoDB execution operators to cause a denial of service.

The issue affects DDP-accessible Admin Panel query surfaces, and user interaction is not required. On real MongoDB deployments, injected $where expressions may be evaluated once per scanned document.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 10.82

External References

Related Security Bulletins