Authorization Flaw in WeKan Project Management Tool
CVE-2026-25566
7.1HIGH
What is CVE-2026-25566?
An authorization vulnerability exists in WeKan that allows users to move cards between different boards, lists, or swimlanes without proper validation of permissions or checks on the destination objects. This flaw could enable unauthorized access and manipulation of cards across boards, posing a significant risk to data integrity and security.
Affected Version(s)
WeKan 0 < 8.19
