Incorrect authorization in Wekan - #VU150014
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to move swimlanes without write permission.
The vulnerability exists due to incorrect authorization in the moveSwimlane Meteor method when moving swimlanes. A remote user can invoke moveSwimlane with source-board membership to move swimlanes without write permission.
Comment-only members are among the affected roles.