CVE-2026-25564: WeKan < 8.19 Checklist Deletion IDOR via Missing Relationship Validation
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeKanto a version that resolves this vulnerability.Fixed in 8.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25564?
CVE-2026-25564 has a medium severity rating due to the potential for unauthorized data access in WeKan.
How do I fix CVE-2026-25564?
To fix CVE-2026-25564, you should upgrade to WeKan version 8.19 or later, which includes the necessary security validation.
What are the affected versions of WeKan for CVE-2026-25564?
CVE-2026-25564 affects WeKan versions prior to 8.19.
What kind of vulnerability is CVE-2026-25564?
CVE-2026-25564 is an insecure direct object reference (IDOR) vulnerability related to checklist creation in WeKan.
What is the impact of CVE-2026-25564 on users?
The impact of CVE-2026-25564 allows unauthorized users to potentially manipulate checklists across different boards in WeKan.