Junglewise Threat Intelligence

CVE-2026-59154: Wekan authorization bypass in Checklists and ChecklistItems

CVE-2026-59154 · Severity: medium · CVSS 4.3 · Published 2026-07-10

Technologies: WeKan. Vendors: WeKan.

Executive brief

Wekan is an open-source project management tool used to organize tasks on digital boards. A security flaw allows a user who has access to at least one board to move task checklists into other private boards where they are not a member. This could allow an unauthorized person to inject data or manipulate the contents of private project boards if they know the ID of a card on that board.

Technical details

Wekan prior to version 9.64 is vulnerable to an authorization bypass (CWE-863) within the Meteor DDP collection 'allow' rules for Checklists and ChecklistItems. The vulnerability exists because the server-side validation only checks if the user has write access to the source card's board, but fails to inspect the update modifier for a new destination cardId or boardId. By directly interacting with the DDP collection and bypassing the 'moveChecklist' Meteor method, an authenticated attacker with write access to any board can move their own checklist items to a private board, provided they know the target card's ID. Once moved, the 'before.update' hook automatically re-assigns the checklist's boardId to match the destination card, effectively injecting the attacker's data into the victim's private board. This has been patched in version 9.64 by implementing destination-aware 'deny' rules.

Affected products

  • Wekan Wekan < 9.64

Timeline

  • 2026-06-20: patched: Fix committed and version 9.64 released
  • 2026-07-10: disclosed: CVE-2026-59154 published

References

Related threats