Executive brief
Wekan, an open-source Kanban board application, contained a security flaw in its OpenID Connect (OIDC) authentication component. This vulnerability allowed regular logged-in users to perform administrative actions, such as creating or modifying organizations and teams, without proper authorization. In certain configurations, an attacker could exploit this to grant themselves full global administrator privileges, potentially leading to a complete takeover of the Wekan instance and all its data.
Technical details
Six Meteor methods used in the OIDC login flow (setCreateOrgFromOidc, setOrgAllFieldsFromOidc, setCreateTeamFromOidc, setTeamAllFieldsFromOidc, boardRoutineOnLogin, and groupRoutineOnLogin) were registered as globally DDP-callable without the admin authorization checks present in their non-OIDC counterparts. An authenticated attacker could invoke these methods directly via the browser console or DDP clients. Specifically, if the PROPAGATE_OIDC_DATA environment variable was enabled, groupRoutineOnLogin could be abused to set the 'isAdmin' flag to true for the attacker's account. The fix, introduced in version 9.32, ensures these methods only execute when called server-to-server (where this.connection is null) and rejects direct client-side DDP invocations.
Affected products
- Wekan Wekan < 9.32
Timeline
- 2026-05-30: advisory: GHSA-cv95-8h7c-2ffq published
- 2026-05-31: patched: Version 9.32 released
- 2026-07-15: disclosed: CVE-2026-53444 published to NVD