Information disclosure in Wekan - #VU147307
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the user-authenticationMethod Meteor DDP publication when handling unauthenticated DDP subscription requests. A remote attacker can subscribe using an arbitrary user ID, email address, or username to disclose sensitive information.
The exposed fields include authentication methods, team memberships, and organization memberships.