CVE-2026-25566
WeKan < 8.19 Cross-board Card Move Without Destination Authorization
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves.
| CWE | CWE-863 |
| Vendor | wekan |
| Product | wekan |
| Published | Feb 7, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for wekan wekan
Be the first to know when new unknown vulnerabilities affecting wekan wekan are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WeKan / WeKan
0 < 8.19
References
Credits
Joshua Rogers