Authorization bypass through user-controlled key in Wekan - #VU150020
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose private-board card information.
The vulnerability exists due to authorization bypass through a user-controlled key in the comment creation endpoint when submitting a comment request with a card ID belonging to another board. A remote user can create a comment associated with a private-board card to disclose private-board card information.
Lazy DDP publication can make the injected comment visible in the victim interface on large boards.