CVE-2026-1964

Discovered by AISLEPUBLISHEDCWE-284CWE-266

Description

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. Patch name: 545566f5663545d16174e0f2399f231aa693ab6e. It is advisable to upgrade the affected component.

CVSS Base Scores

CVSS v4.05.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

CVSS v3.1
4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C

CVSS v3.04.3

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C

CVSS v2.04.0

AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:OF/RC:C

Affected Products

VendorProductVersionStatus
n/aWeKan8.0affected
n/aWeKan8.1affected
n/aWeKan8.2affected
n/aWeKan8.3affected
n/aWeKan8.4affected
n/aWeKan8.5affected
n/aWeKan8.6affected
n/aWeKan8.7affected
n/aWeKan8.8affected
n/aWeKan8.9affected
n/aWeKan8.10affected
n/aWeKan8.11affected
n/aWeKan8.12affected
n/aWeKan8.13affected
n/aWeKan8.14affected
n/aWeKan8.15affected
n/aWeKan8.16affected
n/aWeKan8.17affected
n/aWeKan8.18affected
n/aWeKan8.19affected
n/aWeKan8.20affected
n/aWeKan8.21unaffected

Credits

  • MegaManSec (VulDB User)(reporter)

References