CVE-2026-25859: WeKan < 8.20 Migration Functionality Insufficient Permission Checks
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wekan/wekanto a version that resolves this vulnerability.Fixed in 8.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25859?
CVE-2026-25859 is considered a medium severity vulnerability due to the potential for unauthorized migration operations.
How do I fix CVE-2026-25859?
To fix CVE-2026-25859, upgrade to WeKan version 8.20 or later, which includes the necessary permission checks.
Who is affected by CVE-2026-25859?
CVE-2026-25859 affects all WeKan installations prior to version 8.20 that allow non-administrative users to access migration functionality.
What are the potential risks of CVE-2026-25859?
The risks of CVE-2026-25859 include unauthorized data migration and potential data loss or corruption.
Is there a workaround for CVE-2026-25859?
A temporary workaround for CVE-2026-25859 is to restrict non-administrative users from accessing migration functionality until an upgrade can be performed.