CVE-2026-25568: WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeKanto a version that resolves this vulnerability.Fixed in 8.19 - Configuration
Ensure allowPrivateOnly is enabled so the instance configuration setting is enforced; upgrade to WeKan 8.19 or later because prior to 8.19 has an authorization logic vulnerability that allows creation of public boards at board creation time.
WeKan allowPrivateOnly = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25568?
CVE-2026-25568 is classified as a medium severity vulnerability due to the potential unauthorized access to private boards.
How do I fix CVE-2026-25568?
To fix CVE-2026-25568, upgrade to WeKan version 8.19 or later to ensure proper enforcement of the allowPrivateOnly setting.
What types of systems are affected by CVE-2026-25568?
CVE-2026-25568 affects WeKan versions prior to 8.19 that have the allowPrivateOnly setting enabled.
What functionality does CVE-2026-25568 compromise?
CVE-2026-25568 compromises the intended access control by allowing users to create boards that should be private.
Who should be concerned about CVE-2026-25568?
Administrators and users of WeKan versions before 8.19 should be concerned about CVE-2026-25568 and take immediate actions to upgrade.