CVE-2026-2209: WeKan Custom Translation translationBody.js setCreateTranslation improper authorization
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can be launched remotely. Upgrading to version 8.19 is sufficient to fix this issue. The patch is identified as f244a43771f6ebf40218b83b9f46dba6b940d7de. It is suggested to upgrade the affected component.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2209?
CVE-2026-2209 has a medium severity rating due to improper authorization in the setCreateTranslation function.
How do I fix CVE-2026-2209?
To fix CVE-2026-2209, update your WeKan installation to version 8.19 or later.
What versions of WeKan are affected by CVE-2026-2209?
CVE-2026-2209 affects WeKan versions up to and including 8.18.
What does CVE-2026-2209 affect specifically?
CVE-2026-2209 specifically affects the Custom Translation Handler in WeKan, particularly the setCreateTranslation function.
Is there a known exploit for CVE-2026-2209?
As of now, there are no public exploits documented for CVE-2026-2209, but the vulnerability could potentially be exploited by unauthorized users.