Missing Authorization in Wekan - #VU145021
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to modify or delete organization and team configuration records.
The vulnerability exists due to improper access control in the Meteor DDP allow rules for the org and team collections when handling insert, update, or remove operations on documents whose _id matches the caller\'s user ID. A remote user can send crafted DDP method requests to modify or delete organization and team configuration records.
The issue affects authenticated non-admin users and does not require organization or team administration privileges, membership, tenant scoping, or a field-level allowlist.