Information disclosure in Wekan - #VU147307

 

Information disclosure in Wekan - #VU147307

Published: September 7, 2026


Vulnerability identifier: #VU147307
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the user-authenticationMethod Meteor DDP publication when handling unauthenticated DDP subscription requests. A remote attacker can subscribe using an arbitrary user ID, email address, or username to disclose sensitive information.

The exposed fields include authentication methods, team memberships, and organization memberships.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.15

External References

Related Security Bulletins