CVE-2026-25561: WeKan < 8.19 Attachment Upload Object Relationship Validation Bypass
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling attempts to upload attachments with mismatched object relationships.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeKanto a version that resolves this vulnerability.Fixed in 8.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25561?
CVE-2026-25561 is classified as a medium severity vulnerability due to potential unauthorized access through attachment upload.
How do I fix CVE-2026-25561?
To fix CVE-2026-25561, upgrade your WeKan to version 8.19 or later, which addresses the authorization weakness.
What are the potential impacts of CVE-2026-25561?
The potential impacts of CVE-2026-25561 include unauthorized access to sensitive attachments by exploiting weak API validations.
What versions of WeKan are affected by CVE-2026-25561?
CVE-2026-25561 affects all WeKan versions prior to 8.19.
Is CVE-2026-25561 a critical vulnerability?
CVE-2026-25561 is not classified as critical, but it poses significant risks if not addressed due to its nature of mixing object identifiers.