CVE-2026-1964
Discovered by AISLEPUBLISHEDCWE-284CWE-266
Description
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. Patch name: 545566f5663545d16174e0f2399f231aa693ab6e. It is advisable to upgrade the affected component.
CVSS Base Scores
CVSS v4.05.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
CVSS v3.1
4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C
CVSS v3.04.3
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C
CVSS v2.04.0
AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:OF/RC:C
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| n/a | WeKan | 8.0 | affected |
| n/a | WeKan | 8.1 | unaffected |
| n/a | WeKan | 8.2 | — |
| n/a | WeKan | 8.3 | — |
| n/a | WeKan | 8.4 | — |
| n/a | WeKan | 8.5 | — |
| n/a | WeKan | 8.6 | — |
| n/a | WeKan | 8.7 | — |
| n/a | WeKan | 8.8 | — |
| n/a | WeKan | 8.9 | — |
| n/a | WeKan | 8.10 | — |
| n/a | WeKan | 8.11 | — |
| n/a | WeKan | 8.12 | — |
| n/a | WeKan | 8.13 | — |
| n/a | WeKan | 8.14 | — |
| n/a | WeKan | 8.15 | — |
| n/a | WeKan | 8.16 | — |
| n/a | WeKan | 8.17 | — |
| n/a | WeKan | 8.18 | — |
| n/a | WeKan | 8.19 | — |
| n/a | WeKan | 8.20 | — |
| n/a | WeKan | 8.21 | — |
Credits
- MegaManSec (VulDB User)(reporter)