Improper Authorization in WeKan REST API Affecting Versions Up to 8.20
CVE-2026-1892
What is CVE-2026-1892?
A vulnerability in WeKan has been identified that allows for improper authorization through the function setBoardOrgs in the file models/boards.js. This issue occurs in versions up to 8.20 and enables attackers to manipulate key arguments, such as item.cardId, item.checklistId, and card.boardId. The vulnerability can be exploited remotely and requires a high level of complexity, making it difficult to exploit. To address this issue, users are strongly encouraged to upgrade to version 8.21, which includes a patch (commit cabfeed9a68e21c469bf206d8655941444b9912c) that resolves the vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WeKan 8.0
WeKan 8.1
WeKan 8.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
