LDAP Filter Injection Vulnerability in WeKan by WeKan
CVE-2026-25560
8.7HIGH
What is CVE-2026-25560?
The vulnerability in WeKan allows manipulation of LDAP queries due to inadequate escaping of user-provided username input in LDAP authentication. Attackers could exploit this weakness to craft malicious LDAP search filters, potentially compromising the authentication process. Mitigation has been provided for versions preceding 8.19, emphasizing the importance of upgrading to secure deployments.
Affected Version(s)
WeKan 0 < 8.19
