Authorization bypass through user-controlled key in Wekan - #VU145037

 

Authorization bypass through user-controlled key in Wekan - #VU145037

Published: August 25, 2026


Vulnerability identifier: #VU145037
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in subtaskItems export queries across the board export endpoints when exporting a public board. A remote user can set the parentId field on a private card to reference a card on a public board and then download the public board export to disclose sensitive information.

All five export formats are affected, and no user interaction is required.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.11

External References

Related Security Bulletins