CVE-2026-25566

W

eKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves.

Configurations

Configuration 1 (hide)

cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:*

History

18 Feb 2026, 20:43

Type Values Removed Values Added
Summary
  • (es) Las versiones de WeKan anteriores a la 8.19 contienen una vulnerabilidad de autorización en la lógica de movimiento de tarjetas. Un usuario puede especificar un tablero/lista/carril de destino sin comprobaciones de autorización adecuadas para el destino y sin validar que los objetos de destino pertenezcan al tablero de destino, lo que podría permitir movimientos no autorizados entre tableros.
First Time Wekan Project wekan
Wekan Project
References () https://github.com/wekan/wekan/commit/198509e7600981400353aec6259247b3c04e043e - () https://github.com/wekan/wekan/commit/198509e7600981400353aec6259247b3c04e043e - Patch
References () https://wekan.fi/ - () https://wekan.fi/ - Product
References () https://www.vulncheck.com/advisories/wekan-cross-board-card-move-without-destination-authorization - () https://www.vulncheck.com/advisories/wekan-cross-board-card-move-without-destination-authorization - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:*

07 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-07 22:16

Updated : 2026-02-18 20:43


NVD link : CVE-2026-25566

Mitre link : CVE-2026-25566

CVE.ORG link : CVE-2026-25566


JSON object : View

Products Affected
CWE
CWE-863

Incorrect Authorization