Missing Authorization in Wekan - #VU150004
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose avatar images.
The vulnerability exists due to missing authorization in the Avatars collection download handler when processing library-native avatar download URLs. A remote attacker can request a full-size avatar image using a valid avatar file identifier to disclose avatar images.
The library middleware handles the three-segment download URL before WeKan\'s avatar authorization routes execute.