7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Description
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.
Basic Information
ID
CVE-2026-25564
Source
VulnCheck
Published
Feb 7, 2026 at 21:57
Affected Product
Vendor
WeKan
Product
WeKan
Affected Versions
WeKan WeKan 0