Data Exposure Vulnerability in Wekan Kanban Tool by Open Source Vendor
CVE-2026-30845
6.9MEDIUM
What is CVE-2026-30845?
Wekan, an open-source kanban tool, has a significant vulnerability in versions 8.31.0 to 8.33 that allows unauthorized access to sensitive board data. The composite publication mechanism fails to filter sensitive information, including webhook URLs and authentication tokens, making them accessible to all board members and even unauthenticated users on public boards. This security flaw poses a risk as it enables attackers to exploit exposed webhooks for unauthorized actions in external integrations. Users are advised to upgrade to version 8.34 or later to mitigate this risk.
Affected Version(s)
Wekan >= 8.31.0, < 8.34
