CVE 7.1 HIGH

WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass_CVE-2026-25568

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.

Basic Information

ID CVE-2026-25568
Source VulnCheck
Published Feb 7, 2026 at 21:59

Affected Product

Vendor WeKan
Product WeKan
Affected Versions WeKan WeKan 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.