Improper Authentication in Wekan - #VU145038
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to take over an existing account.
The vulnerability exists due to improper authentication in the CAS login handler in packages/wekan-accounts-cas/cas_server.js when processing CAS-authenticated logins with a username matching an existing local account. A remote user can authenticate through the configured CAS server with a matching username to take over an existing account.
Only instances with CAS enabled are vulnerable, and no victim interaction is required.