🔐 CVE Alert

CVE-2026-41454

HIGH 8.3

WeKan < 8.35 Missing Authorization via Integration REST API

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

CWE CWE-862
Vendor wekan
Product wekan
Published Apr 22, 2026
Last Updated Apr 22, 2026
Stay Ahead of the Next One

Get instant alerts for wekan wekan

Be the first to know when new high vulnerabilities affecting wekan wekan are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

wekan / wekan
0 < 8.35.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/wekan/wekan/releases/tag/v8.35 github.com: https://github.com/wekan/wekan/commit/2cd702f48df2b8aef0e7381685f8e089986a18a4 vulncheck.com: https://www.vulncheck.com/advisories/wekan-missing-authorization-via-integration-rest-api

Credits

Rodolphe GHIO xet7