Incorrect authorization in Wekan - #VU150011
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to regain access to a private board after removal.
The vulnerability exists due to improper authorization in the acceptInvite method when processing a client-writable profile.invitedBoards value. A remote user can add a private board identifier to their profile.invitedBoards array and invoke acceptInvite to regain access to a private board after removal.
Exploitation is limited to users whose existing board membership record was deactivated rather than removed.