CVE-2026-1964

Discovered by AISLEPUBLISHEDCWE-284CWE-266

Description

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. Patch name: 545566f5663545d16174e0f2399f231aa693ab6e. It is advisable to upgrade the affected component.

CVSS Base Scores

CVSS v4.05.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

CVSS v3.1
4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C

CVSS v3.04.3

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C

CVSS v2.04.0

AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:OF/RC:C

Affected Products

VendorProductVersionStatus
n/aWeKan8.0affected
n/aWeKan8.1unaffected
n/aWeKan8.2
n/aWeKan8.3
n/aWeKan8.4
n/aWeKan8.5
n/aWeKan8.6
n/aWeKan8.7
n/aWeKan8.8
n/aWeKan8.9
n/aWeKan8.10
n/aWeKan8.11
n/aWeKan8.12
n/aWeKan8.13
n/aWeKan8.14
n/aWeKan8.15
n/aWeKan8.16
n/aWeKan8.17
n/aWeKan8.18
n/aWeKan8.19
n/aWeKan8.20
n/aWeKan8.21

Credits

  • MegaManSec (VulDB User)(reporter)

References