Improper access control in Wekan - #VU145031
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the user-search DDP publication when handling subscription requests. A remote user can subscribe with a wildcard search pattern to disclose sensitive information.
The issue exposes email addresses, admin status, disabled status, authentication methods, and org or team memberships across the entire instance without board-level scoping.