Missing Authentication for Critical Function in Wekan - #VU145034
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication for the user-miniprofile Meteor DDP publication in server/publications/users.js when handling unauthenticated WebSocket subscription requests. A remote attacker can subscribe to the user-miniprofile publication with supplied usernames to disclose sensitive information.
Exposed data may include org and team membership, authentication method, last connection date, and migration-era usernames.