CVE Database
/

CVE-2026-25566

Back to search

CVE-2026-25566

Published: Feb 7, 2026

Modified: May 11, 2026

PUBLISHED

Description

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves.

VendorProductVersions

WeKan

WeKan

affected
0 - < 8.19

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now