CVE-2026-25566: WeKan < 8.19 Cross-board Card Move Without Destination Authorization
WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeKanto a version that resolves this vulnerability.Fixed in 8.19 - Compensating control
Restrict the ability to perform cross-board card moves (e.g., via application access controls/permissions) until WeKan is upgraded to 8.19, to reduce exposure to unauthorized destination moves.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25566?
The severity of CVE-2026-25566 is classified as medium, indicating a moderate risk associated with the vulnerability.
How do I fix CVE-2026-25566?
To fix CVE-2026-25566, upgrade WeKan to version 8.19 or later, which includes the necessary authorization checks.
What does CVE-2026-25566 affect?
CVE-2026-25566 affects WeKan versions prior to 8.19, specifically involving the card move functionality.
What is the nature of the vulnerability in CVE-2026-25566?
CVE-2026-25566 is an authorization vulnerability that allows a user to move cards to a destination without proper permission checks.
Who is vulnerable to CVE-2026-25566?
Users running WeKan versions prior to 8.19 are vulnerable to CVE-2026-25566 due to the lack of destination authorization in card movement.