Incorrect authorization in Wekan - #VU150015
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to reparent checklists without write permission.
The vulnerability exists due to incorrect authorization in the moveChecklist Meteor method when moving a checklist between cards. A remote user can invoke moveChecklist while being a member associated with both cards to reparent checklists without write permission.
The user interface normally hides this operation behind canModifyCard.