CVE-2026-25560: WeKan < 8.19 LDAP Authentication Filter Injection
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeKanto a version that resolves this vulnerability.Fixed in 8.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25560?
CVE-2026-25560 has been classified as a medium severity vulnerability due to the potential for unauthorized access through LDAP filter injection.
How do I fix CVE-2026-25560?
To mitigate CVE-2026-25560, users should upgrade their WeKan installation to version 8.19 or later, which addresses the LDAP authentication filter injection issue.
What versions of WeKan are affected by CVE-2026-25560?
CVE-2026-25560 affects all versions of WeKan prior to 8.19.
What type of vulnerability is CVE-2026-25560?
CVE-2026-25560 is an LDAP authentication filter injection vulnerability.
Can CVE-2026-25560 lead to data breaches?
Yes, CVE-2026-25560 can potentially lead to data breaches by allowing attackers to manipulate LDAP queries to gain unauthorized access to the system.