Incorrect authorization in Wekan - #VU150012

 

Incorrect authorization in Wekan - #VU150012

Published: September 15, 2026


Vulnerability identifier: #VU150012
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify board settings.

The vulnerability exists due to incorrect authorization in the REST board management endpoints when handling requests from normal board members. A remote user can send requests to update a board title or card settings, or create, modify, or delete board rules to modify board settings.

Board rules can configure automation that later runs as trusted server code.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.77

External References

Related Security Bulletins