Executive brief
Wekan is an open-source project management tool used by teams to organize tasks on digital boards. A security flaw allows any registered user to move their own tasks, lists, or categories into private boards belonging to other users or teams, even if they are not members of those boards. This could allow an attacker to disrupt operations or inject unauthorized content into sensitive private projects.
Technical details
Wekan's DDP (Distributed Data Protocol) update allow rules in 'server/permissions/cards.js', 'lists.js', and 'swimlanes.js' fail to validate the destination 'boardId' during an update operation. The application only checks if the user has write access to the document's current (source) board. An authenticated attacker can use a DDP client to call '/cards/update' (or similar) and use a '$set' modifier to change the 'boardId' to that of a victim's private board. This results in a cross-board write that bypasses board-level membership restrictions. The REST API is not affected as it correctly validates the destination board. The issue is fixed in version 9.37 by implementing a 'deny' rule that rejects updates modifying a 'boardId' to a destination where the user lacks write access.
Affected products
- Wekan Wekan < 9.37
Timeline
- 2026-06-11: patched: Fixed in version 9.37
- 2026-06-11: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: CVE-2026-55234 published to NVD