Authorization bypass through user-controlled key in Wekan - #VU145037
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in subtaskItems export queries across the board export endpoints when exporting a public board. A remote user can set the parentId field on a private card to reference a card on a public board and then download the public board export to disclose sensitive information.
All five export formats are affected, and no user interaction is required.