Vulnerability Description
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update modifier. Any authenticated user with write access to their own board can call /cards/update, /lists/update, or /swimlanes/update to move cards, lists, or swimlanes into a private board they are not a member of. This issue is fixed in version 9.37.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/wekan/wekan/commit/d369a3614a4737c29d48a6345a790edf2506ddae
- https://github.com/wekan/wekan/releases/tag/v9.37
- https://github.com/wekan/wekan/security/advisories/GHSA-gm7v-pc38-53jr
- https://github.com/wekan/wekan/security/advisories/GHSA-gm7v-pc38-53jr
FAQ
What is CVE-2026-55234?
CVE-2026-55234 is a vulnerability with a CVSS score of 8.5 (HIGH). Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize ag...
How severe is CVE-2026-55234?
CVE-2026-55234 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55234?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.