Vulnerability Description
WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wekan Project | Wekan | < 8.19 |
Related Weaknesses (CWE)
References
- https://github.com/wekan/wekan/commit/198509e7600981400353aec6259247b3c04e043ePatch
- https://wekan.fi/Product
- https://www.vulncheck.com/advisories/wekan-cross-board-card-move-without-destinaThird Party Advisory
FAQ
What is CVE-2026-25566?
CVE-2026-25566 is a vulnerability with a CVSS score of 5.4 (MEDIUM). WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination a...
How severe is CVE-2026-25566?
CVE-2026-25566 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25566?
Check the references section above for vendor advisories and patch information. Affected products include: Wekan Project Wekan.