CVE 7.1 HIGH

WeKan < 8.19 Checklist Creation Cross-Board IDOR_CVE-2026-25563

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.

Basic Information

ID CVE-2026-25563
Source VulnCheck
Published Feb 7, 2026 at 21:57

Affected Product

Vendor WeKan
Product WeKan
Affected Versions WeKan WeKan 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.