Information disclosure in Wekan - #VU144216

 

Information disclosure in Wekan - #VU144216

Published: August 18, 2026


Vulnerability identifier: #VU144216
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose low-sensitivity board metadata.

The vulnerability exists due to improper access control in the GET /api/users/{userId}/boards endpoint when handling board listing requests for a user whose membership was revoked. A remote user can request their own board listing to disclose low-sensitivity board metadata.

The exposure is limited to the board id and title, and title changes remain visible after membership is deactivated. Access to board contents is still denied.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 10.92

External References

Related Security Bulletins