CVE 5.3 MEDIUM

WeKan Attachment Storage lists.js applyWipLimit ListWIPBleed access control_CVE-2026-1895

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

Description

A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. Upgrading to version 8.21 is able to address this issue. This patch is called 8c0b4f79d8582932528ec2fdf2a4487c86770fb9. It is recommended to upgrade the affected component.

Basic Information

ID CVE-2026-1895
Source VulDB
Published Feb 4, 2026 at 23:02

Affected Product

Vendor n/a
Product WeKan
Version 8.0
Affected Versions n/a WeKan 8.0
n/a WeKan 8.1
n/a WeKan 8.2
n/a WeKan 8.3
n/a WeKan 8.4
n/a WeKan 8.5
n/a WeKan 8.6
n/a WeKan 8.7
n/a WeKan 8.8
n/a WeKan 8.9
n/a WeKan 8.10
n/a WeKan 8.11
n/a WeKan 8.12
n/a WeKan 8.13
n/a WeKan 8.14
n/a WeKan 8.15
n/a WeKan 8.16
n/a WeKan 8.17
n/a WeKan 8.18
n/a WeKan 8.19
n/a WeKan 8.20

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.