Improper Authorization in WeKan REST API Affecting Versions Up to 8.20
CVE-2026-1892

2.3LOW

Key Information:

Vendor

WeKan

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-1892?

A vulnerability in WeKan has been identified that allows for improper authorization through the function setBoardOrgs in the file models/boards.js. This issue occurs in versions up to 8.20 and enables attackers to manipulate key arguments, such as item.cardId, item.checklistId, and card.boardId. The vulnerability can be exploited remotely and requires a high level of complexity, making it difficult to exploit. To address this issue, users are strongly encouraged to upgrade to version 8.21, which includes a patch (commit cabfeed9a68e21c469bf206d8655941444b9912c) that resolves the vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WeKan 8.0

WeKan 8.1

WeKan 8.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MegaManSec (VulDB User)
.