Incorrect authorization in Wekan - #VU150012
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to modify board settings.
The vulnerability exists due to incorrect authorization in the REST board management endpoints when handling requests from normal board members. A remote user can send requests to update a board title or card settings, or create, modify, or delete board rules to modify board settings.
Board rules can configure automation that later runs as trusted server code.