Vulnerability Description
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wekan Project | Wekan | < 8.20 |
Related Weaknesses (CWE)
References
- https://github.com/wekan/wekan/commit/cbb1cd78de3e40264a5e047ace0ce27f8635b4e6Patch
- https://wekan.fi/Product
- https://www.vulncheck.com/advisories/wekan-migration-functionality-insufficient-Third Party Advisory
FAQ
What is CVE-2026-25859?
CVE-2026-25859 is a vulnerability with a CVSS score of 8.8 (HIGH). Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.
How severe is CVE-2026-25859?
CVE-2026-25859 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25859?
Check the references section above for vendor advisories and patch information. Affected products include: Wekan Project Wekan.