Authorization bypass through user-controlled key in Wekan - #VU150021
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data on an unauthorized board.
The vulnerability exists due to authorization bypass through a user-controlled key in the subtasksDefaultBoardId handling and board publication scope when setting a source board\'s subtasksDefaultBoardId to another board identifier. A remote user can set the identifier to a board they cannot access and subscribe to the source board to receive cards and related board content from the other board.
Content may be disclosed to all subscribers of the source board, including anonymous users when that board is public.