CVE-2026-41454: WeKan < 8.35 Missing Authorization via Integration REST API
WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41454?
CVE-2026-41454 is classified with a high severity due to its potential for allowing unauthorized administrative actions.
How do I fix CVE-2026-41454?
To fix CVE-2026-41454, upgrade to WeKan version 8.35 or later, which includes the necessary authorization enhancements.
Who is affected by CVE-2026-41454?
Authenticated board members in WeKan versions below 8.35 are affected by CVE-2026-41454.
What actions can attackers perform due to CVE-2026-41454?
Attackers can perform administrative actions without proper privilege verification due to CVE-2026-41454.
What is WeKan in relation to CVE-2026-41454?
WeKan is an open-source kanban board application that is vulnerable to missing authorization via its Integration REST API in versions prior to 8.35.