GHSL-2026-044: Unauthorized Data Manipulation in Wekan - CVE-2026-30843
Wekan v8.32 is vulnerable to an Insecure Direct Object Reference (IDOR) issue (GHSL-2026-044) in the custom fields update endpoints, which could allow unauthorized users to modify custom fields across boards, potentially leading to unauthorized data manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2026-044?
GHSL-2026-044 has a risk rating of 45, indicating a significant vulnerability.
How do I fix GHSL-2026-044?
To mitigate GHSL-2026-044, upgrade to Wekan version 8.34 or later where the issue has been resolved.
Who is affected by GHSL-2026-044?
Any user of Wekan version 8.32 is potentially affected by GHSL-2026-044 due to the insecure design of custom fields update endpoints.
What type of vulnerability is GHSL-2026-044?
GHSL-2026-044 is categorized as an Insecure Direct Object Reference (IDOR) vulnerability.
What are the potential impacts of GHSL-2026-044?
GHSL-2026-044 could lead to unauthorized data manipulation, allowing users to change custom fields across different boards.