Incorrect authorization in Wekan - #VU145023
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to modify card content.
The vulnerability exists due to incorrect authorization in the REST API card update endpoint when handling authenticated card modification requests. A remote user can send a crafted PUT request for an unassigned card to modify card content.
No cross-board access, confidentiality impact, or site-administrator escalation was observed during testing.