Executive brief
WeKan, an open-source Kanban board used for project management, contains a security flaw in its login system. An attacker can provide specially crafted usernames to manipulate the internal database queries used during authentication. This could allow an unauthorized person to bypass security checks, potentially gaining access to sensitive project data or user accounts.
Technical details
An LDAP injection vulnerability exists in WeKan's LDAP authentication module (specifically within packages/wekan-ldap/server/ldap.js). The application fails to properly sanitize or escape user-supplied username input before incorporating it into LDAP search filters and Distinguished Name (DN) related values. A remote, unauthenticated attacker can exploit this by submitting crafted authentication requests to manipulate the resulting LDAP query. This can lead to authentication bypass or unauthorized information disclosure from the LDAP directory. The issue is resolved in version 8.19 by implementing proper escaping for the User_Search_Field.
Affected products
- WeKan WeKan < 8.19
Timeline
- 2026-02-07: disclosed
- 2026-02-07: patched: Fixed in version 8.19
- 2026-02-07: advisory