CVE-2026-1894

MEDIUM

Wekan < 8.21 - Improper Authorization via REST API Checklist Items Manipulation

Title source: llm
STIX 2.1

Description

A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Performing a manipulation of the argument item.cardId/item.checklistId/card.boardId results in improper authorization. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. The patch is named 251d49eea94834cf351bb395808f4a56fb4dbb44. Upgrading the affected component is recommended.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.344266
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.344266
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.742663

Scores

CVSS v3 6.3
EPSS 0.0024
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-266
Status published
Products (1)
wekan_project/wekan < 8.21
Published Feb 04, 2026
Tracked Since Feb 18, 2026