Home

Description

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier.

PUBLISHED Reserved 2026-02-02 | Published 2026-02-07 | Updated 2026-02-10 | Assigner VulnCheck




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

Product status

Default status
unaffected

Any version before 8.19
affected

Credits

Joshua Rogers finder

References

github.com/...ommit/67cb47173c1a152d9eaf5469740992b2dacdf62d patch

wekan.fi/ product

www.vulncheck.com/...r-spoofing-via-user-controlled-authorid third-party-advisory

cve.org (CVE-2026-25567)

nvd.nist.gov (CVE-2026-25567)

Download JSON