Data Exposure Vulnerability in Wekan Kanban Tool by Open Source Vendor
CVE-2026-30845

6.9MEDIUM

Key Information:

Vendor

Wekan

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-30845?

Wekan, an open-source kanban tool, has a significant vulnerability in versions 8.31.0 to 8.33 that allows unauthorized access to sensitive board data. The composite publication mechanism fails to filter sensitive information, including webhook URLs and authentication tokens, making them accessible to all board members and even unauthenticated users on public boards. This security flaw poses a risk as it enables attackers to exploit exposed webhooks for unauthorized actions in external integrations. Users are advised to upgrade to version 8.34 or later to mitigate this risk.

Affected Version(s)

Wekan >= 8.31.0, < 8.34

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.