Junglewise Threat Intelligence

CVE-2026-25563: WeKan IDOR in checklist creation

CVE-2026-25563 · Severity: high · CVSS 7.5 · Published 2026-02-07

Technologies: WeKan. Vendors: WeKan.

Executive brief

WeKan is an open-source project management tool used to organize tasks on visual boards. A security flaw in versions prior to 8.19 allows users to manipulate task identifiers to create or modify checklists on boards they may not have permission to access. This could lead to unauthorized data modification and disruption of project workflows across different teams or departments.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in WeKan's checklist creation and related API routes. The application fails to validate that a provided 'cardId' actually belongs to the specified 'boardId' during request processing. A remote attacker can exploit this by manipulating these identifiers in network requests to perform actions on cards across different boards. This bypasses intended authorization boundaries, allowing for unauthorized checklist modifications. The issue is addressed in version 8.19 by implementing server-side checks to verify card-to-board ownership.

Affected products

  • WeKan WeKan < 8.19

Timeline

  • 2026-02-07: disclosed
  • 2026-02-07: advisory
  • 2026-02-07: patched: Fixed in version 8.19

References

Related threats