Authorization Weakness in WeKan's Attachment Upload API
CVE-2026-25561
7.1HIGH
What is CVE-2026-25561?
WeKan versions prior to 8.19 exhibit a significant flaw in their attachment upload API, allowing malicious entities to upload files with incorrect identifiers. This authorization weakness arises from insufficient validation of identifiers such as boardId, cardId, swimlaneId, and listId. As a result, attackers may leverage this loophole to create attachments that do not correlate with the intended objects, potentially compromising data integrity and security within the WeKan platform.
Affected Version(s)
WeKan 0 < 8.19
