Improper Authorization in Wekan - #VU145026
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to create cards and checklists without write permission.
The vulnerability exists due to improper authorization in card creation and checklist creation REST endpoints when handling authenticated API requests from restricted board members. A remote user can send crafted POST requests to create cards and checklists without write permission.
The issue affects members assigned the comment-only, comment-assigned-only, or worker roles on boards where those roles have comment capability but explicitly lack write capability.