CVE Database
/

CVE-2026-25565

Back to search

CVE-2026-25565

Published: Feb 7, 2026

Modified: May 11, 2026

PUBLISHED

Description

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.

VendorProductVersions

WeKan

WeKan

affected
0 - < 8.19

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now