GHSL-2026-035: Wekan may Leak Credentials During User Notification Workflow - CVE-2026-30847
Wekan v8.31.0 is vulnerable to a credential leakage issue (GHSL-2026-035), where sensitive user credentials could be exposed through the notificationUsers publication, potentially leading to unauthorized access and data compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2026-035?
The severity of GHSL-2026-035 is rated at 55, indicating a significant risk of credential leakage.
How do I fix GHSL-2026-035?
To fix GHSL-2026-035, update Wekan to version 8.34 or later, which addresses this credential leakage issue.
What specific issue does GHSL-2026-035 describe?
GHSL-2026-035 describes a vulnerability in Wekan where sensitive user credentials may be exposed during the user notification workflow.
What version of Wekan is affected by GHSL-2026-035?
Wekan version 8.31.0 is affected by the GHSL-2026-035 vulnerability.
What could happen if GHSL-2026-035 is exploited?
If GHSL-2026-035 is exploited, it could lead to unauthorized access to user accounts and potential data compromise.