Missing Authorization in Wekan - #VU150005
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose user profile photos.
The vulnerability exists due to missing authorization in the serveLegacyAvatar function and legacy avatar file-serving routes when handling requests for legacy CollectionFS avatar file-record identifiers. A remote attacker can send a request for a legacy avatar file-record identifier to disclose user profile photos.
Exploitation requires an instance containing legacy CollectionFS avatar data and knowledge of or the ability to enumerate a legacy avatar file-record identifier.