CVE-2026-2208: WeKan Rules rules.js RulesBleed authorization
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remotely. Upgrading to version 8.21 is recommended to address this issue. The identifier of the patch is a787bcddf33ca28afb13ff5ea9a4cb92dceac005. The affected component should be upgraded.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2208?
The severity of CVE-2026-2208 is considered critical due to the lack of authorization in the Rules Handler which can be exploited remotely.
How do I fix CVE-2026-2208?
To fix CVE-2026-2208, update your WeKan installation to version 8.21 or later, which addresses this vulnerability.
What specific component is affected by CVE-2026-2208?
CVE-2026-2208 affects the rules.js file within the Rules Handler component of WeKan.
Can CVE-2026-2208 be exploited remotely?
Yes, CVE-2026-2208 can be exploited remotely due to the missing authorization in the application.
Which versions of WeKan are impacted by CVE-2026-2208?
WeKan versions up to and including 8.20 are impacted by CVE-2026-2208.