Authorization Bypass Through User-Controlled SQL Primary Key in Wekan - #VU147308

 

Authorization Bypass Through User-Controlled SQL Primary Key in Wekan - #VU147308

Published: September 7, 2026


Vulnerability identifier: #VU147308
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-566
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to take over arbitrary Wekan accounts.

The vulnerability exists due to improper authorization in the OIDC login handler\'s Object.assign merge of JWT claims into serviceData when processing an OIDC login with attacker-controlled JWT claims. A remote user can supply a JWT claim that overwrites an identity field to take over arbitrary Wekan accounts.

Exploitation requires OIDC authentication to be configured and the administrator to whitelist an identity field such as id, username, or email.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.15

External References

Related Security Bulletins