CVE 7.1 HIGH

WeKan < 8.19 Read-only Board Roles Can Update Cards_CVE-2026-25565

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.

Basic Information

ID CVE-2026-25565
Source VulnCheck
Published Feb 7, 2026 at 21:58

Affected Product

Vendor WeKan
Product WeKan
Affected Versions WeKan WeKan 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.