Privilege Escalation Vulnerability in Wekan Kanban Board System
CVE-2025-65780

Currently unrated

Key Information:

Vendor

Wekan

Vendor
CVE Published:
15 December 2025

What is CVE-2025-65780?

An issue in the Wekan Kanban Board System allows authenticated users to update their entire user document, including organizational details and login statuses, due to insufficient server-side authorization checks. This flaw enables a potential for privilege escalation and unauthorized access to other teams and organizations, posing significant security risks for users. The vulnerability impacts all versions up to 18.15 and has been addressed in version 18.16.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.