CVE-2026-1897: WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorization
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from remote. Upgrading to version 8.21 can resolve this issue. The patch is identified as 55576ec17722db094835470b386162c9a662fb60. It is advisable to upgrade the affected component.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1897?
CVE-2026-1897 has been classified with a moderate severity level due to its potential impact on user authorization.
How do I fix CVE-2026-1897?
To mitigate CVE-2026-1897, update WeKan to version 8.21 or later.
What component is affected by CVE-2026-1897?
CVE-2026-1897 affects the Position-History Tracking component within positionHistory.js.
Is CVE-2026-1897 present in the latest version of WeKan?
CVE-2026-1897 is not present in versions of WeKan released after 8.20.
What are the potential impacts of CVE-2026-1897?
The potential impact of CVE-2026-1897 includes unauthorized access to user position history.