Authorization bypass through user-controlled key in Wekan - #VU145036

 

Authorization bypass through user-controlled key in Wekan - #VU145036

Published: August 25, 2026


Vulnerability identifier: #VU145036
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject a card they control into an arbitrary private board and disclose limited board structure information.

The vulnerability exists due to authorization bypass through a user-controlled key in the UserPositionHistory insert allow rule and undo() helper when processing a crafted userPositionHistory record and undo request. A remote user can insert a crafted history entry with an attacker-controlled previousBoardId and invoke undo to inject a card they control into an arbitrary private board and disclose limited board structure information.

The injected card may contain attacker-authored title, description, custom fields, and attachments, and it becomes visible in the victim board activity feed. Supplying valid previousListId or previousSwimlaneId values is required, and errors may reveal target board structure.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.11

External References

Related Security Bulletins