Authorization bypass through user-controlled key in Wekan - #VU144220

 

Authorization bypass through user-controlled key in Wekan - #VU144220

Published: August 18, 2026


Vulnerability identifier: #VU144220
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete card-related data across boards.

The vulnerability exists due to authorization bypass through user-controlled key in the single-card DELETE endpoint when handling a request that supplies an accessible board ID in the URL and a foreign card ID in the path. A remote user can send a crafted DELETE request to delete card-related data across boards.

Deletion is irreversible, the targeted card itself may remain present, and the endpoint can return HTTP 200 even when only the related comments, checklists, checklist items, activities, and subcards were removed. Only deployments with WITH_API=true are vulnerable.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 10.92

External References

Related Security Bulletins