CVE-2026-52893
CRITICALWekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook
Title source: cnaDescription
Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing Wekan user, without verifying ownership or checking email_verified. An attacker using an OIDC provider account with a victim's email or username can cause Wekan to merge the attacker's OIDC credentials into the victim account and then log in as that account. This issue is fixed in version 9.32.
References (3)
Core 3
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/wekan/wekan/releases/tag/v9.32
X_Refsource_Confirm x_refsource_confirm
https://github.com/wekan/wekan/security/advisories/GHSA-mp7g-hj5q-gxhq
X_Refsource_Misc x_refsource_misc
https://github.com/wekan/wekan/commit/73204d4e0a7d77a1b186b3d76e8eaf2f3e7c9fd9
Scores
CVSS v4
9.2
EPSS
0.0030
EPSS Percentile
22.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (1)
wekan/wekan
< 9.32
Published
Jul 15, 2026
Tracked Since
Jul 16, 2026