Authorization bypass through user-controlled key in Wekan - #VU150019
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to modify cards on private boards.
The vulnerability exists due to authorization bypass through a user-controlled key in the rules.runButton method when invoking a button rule with an unbound card ID. A remote user can invoke the method with a rule ID from one board and a card ID from another board to modify cards on private boards.
The user only needs comment-only or read-only membership on the board containing the rule.