Authorization bypass through user-controlled key in Wekan - #VU150021

 

Authorization bypass through user-controlled key in Wekan - #VU150021

Published: September 15, 2026


Vulnerability identifier: #VU150021
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify data on an unauthorized board.

The vulnerability exists due to authorization bypass through a user-controlled key in the subtasksDefaultBoardId handling and board publication scope when setting a source board\'s subtasksDefaultBoardId to another board identifier. A remote user can set the identifier to a board they cannot access and subscribe to the source board to receive cards and related board content from the other board.

Content may be disclosed to all subscribers of the source board, including anonymous users when that board is public.


Affected software

Wekan

Remediation

Install security update from vendor's website.

Wekan - update to 11.77

External References

Related Security Bulletins