Improper Authentication in Wekan - #VU145038

 

Improper Authentication in Wekan - #VU145038

Published: August 25, 2026


Vulnerability identifier: #VU145038
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to take over an existing account.

The vulnerability exists due to improper authentication in the CAS login handler in packages/wekan-accounts-cas/cas_server.js when processing CAS-authenticated logins with a username matching an existing local account. A remote user can authenticate through the configured CAS server with a matching username to take over an existing account.

Only instances with CAS enabled are vulnerable, and no victim interaction is required.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.11

External References

Related Security Bulletins