Improper Authorization in Wekan - #VU145026

 

Improper Authorization in Wekan - #VU145026

Published: August 25, 2026


Vulnerability identifier: #VU145026
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create cards and checklists without write permission.

The vulnerability exists due to improper authorization in card creation and checklist creation REST endpoints when handling authenticated API requests from restricted board members. A remote user can send crafted POST requests to create cards and checklists without write permission.

The issue affects members assigned the comment-only, comment-assigned-only, or worker roles on boards where those roles have comment capability but explicitly lack write capability.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.08

External References

Related Security Bulletins