Authorization bypass through user-controlled key in Wekan - #VU150009
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to private boards.
The vulnerability exists due to improper access control in the sendInvitation method when submitting an invitation with a private board ID. A remote user can submit an invitation containing an arbitrary private board ID to gain unauthorized access to private boards.
Exploitation requires registration to be disabled and mailDomainName to be configured.