CVE-2026-25565: WeKan < 8.19 Read-only Board Roles Can Update Cards
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeKanto a version that resolves this vulnerability.Fixed in 8.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25565?
CVE-2026-25565 has been classified as a medium severity vulnerability due to its potential for misuse by users with read-only access.
How do I fix CVE-2026-25565?
To fix CVE-2026-25565, update WeKan to version 8.19 or later, where the authorization issue has been resolved.
What versions are affected by CVE-2026-25565?
CVE-2026-25565 affects all WeKan versions prior to 8.19.
What type of vulnerability is CVE-2026-25565?
CVE-2026-25565 is an authorization vulnerability allowing unauthorized card updates by users with read-only roles.
Can users with read-only roles exploit CVE-2026-25565?
Yes, users with read-only roles can exploit CVE-2026-25565 to perform unauthorized updates to cards.