Missing Authorization in Wekan - #VU145021

 

Missing Authorization in Wekan - #VU145021

Published: August 25, 2026


Vulnerability identifier: #VU145021
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify or delete organization and team configuration records.

The vulnerability exists due to improper access control in the Meteor DDP allow rules for the org and team collections when handling insert, update, or remove operations on documents whose _id matches the caller\'s user ID. A remote user can send crafted DDP method requests to modify or delete organization and team configuration records.

The issue affects authenticated non-admin users and does not require organization or team administration privileges, membership, tenant scoping, or a field-level allowlist.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.07

External References

Related Security Bulletins