GHSL-2026-037: Authentication Token Leak in Wekan - CVE-2026-30846
Wekan v8.31.0 is vulnerable to a global webhook token leak (GHSL-2026-037) due to improper handling of tokens via pubsub, which could allow attackers to access sensitive webhook information. This vulnerability could result in data breaches or unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2026-037?
The severity of GHSL-2026-037 is rated at 51, indicating a significant risk due to a global webhook token leak.
How do I fix GHSL-2026-037?
To fix GHSL-2026-037, upgrade Wekan to version 8.34 or later which addresses the authentication token leak.
What could happen if GHSL-2026-037 is exploited?
If GHSL-2026-037 is exploited, attackers may gain unauthorized access to sensitive webhook information, potentially resulting in data breaches.
Which version of Wekan is affected by GHSL-2026-037?
Wekan version 8.31.0 is affected by GHSL-2026-037, which involves a vulnerability in handling webhook tokens.
What kind of applications are affected by GHSL-2026-037?
GHSL-2026-037 affects the Wekan application, particularly due to improper token handling in its pubsub mechanism.