CVE 5.3 MEDIUM

WeKan < 8.19 Attachments Publication Information Disclosure_CVE-2026-25562

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to unauthorized users.

Basic Information

ID CVE-2026-25562
Source VulnCheck
Published Feb 7, 2026 at 21:57

Affected Product

Vendor WeKan
Product WeKan
Affected Versions WeKan WeKan 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.