Incorrect authorization in Wekan - #VU150015

 

Incorrect authorization in Wekan - #VU150015

Published: September 15, 2026


Vulnerability identifier: #VU150015
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to reparent checklists without write permission.

The vulnerability exists due to incorrect authorization in the moveChecklist Meteor method when moving a checklist between cards. A remote user can invoke moveChecklist while being a member associated with both cards to reparent checklists without write permission.

The user interface normally hides this operation behind canModifyCard.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.77

External References

Related Security Bulletins