CVE-2026-25568: WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass

Published Feb 7, 2026
·
Updated

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.

Affected Software

2 affected components
wekan/wekan<8.19
Wekan project Wekan<8.19

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WeKan to a version that resolves this vulnerability.

    Fixed in 8.19
  2. Configuration

    Ensure allowPrivateOnly is enabled so the instance configuration setting is enforced; upgrade to WeKan 8.19 or later because prior to 8.19 has an authorization logic vulnerability that allows creation of public boards at board creation time.

    WeKan allowPrivateOnly = enabled

Event History

Feb 7, 2026
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 20, 58090
Event
via FIRST·12:57 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-25568?

CVE-2026-25568 is classified as a medium severity vulnerability due to the potential unauthorized access to private boards.

2

How do I fix CVE-2026-25568?

To fix CVE-2026-25568, upgrade to WeKan version 8.19 or later to ensure proper enforcement of the allowPrivateOnly setting.

3

What types of systems are affected by CVE-2026-25568?

CVE-2026-25568 affects WeKan versions prior to 8.19 that have the allowPrivateOnly setting enabled.

4

What functionality does CVE-2026-25568 compromise?

CVE-2026-25568 compromises the intended access control by allowing users to create boards that should be private.

5

Who should be concerned about CVE-2026-25568?

Administrators and users of WeKan versions before 8.19 should be concerned about CVE-2026-25568 and take immediate actions to upgrade.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203