Authorization bypass through user-controlled key in Wekan - #VU145028

 

Authorization bypass through user-controlled key in Wekan - #VU145028

Published: August 25, 2026


Vulnerability identifier: #VU145028
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create boards under another user\'s account.

The vulnerability exists due to authorization bypass through a user-controlled key in the POST /api/boards endpoint when handling crafted board-creation requests. A remote user can supply a crafted owner field in the request body to create boards under another user\'s account.

The created board appears in the victim\'s board list with the victim as the sole admin, while the requester is not added as a member of that board.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.08

External References

Related Security Bulletins