Incorrect authorization in Wekan - #VU145022
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to create arbitrary cards on a board.
The vulnerability exists due to incorrect authorization in the importIcsToBoard Meteor method in server/methods/icsImport.js when processing ICS import requests. A remote user can invoke the import method with crafted ICS content to create arbitrary cards on a board.
The issue affects comment-only board members and is limited to intra-board integrity impact, with no observed cross-board access or confidentiality impact.