Unverified Ownership in Wekan - #VU144217
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to falsify activity attribution for card creations, card deletions, and custom-field creations.
The vulnerability exists due to unverified ownership in authorId request-body handling in card and custom-field API endpoints when processing authenticated board write requests. A remote user can supply a crafted authorId value to falsify activity attribution for card creations, card deletions, and custom-field creations.
The issue affects board activity history and recorded document ownership on boards the user can write to.