CVE-2026-53447

MEDIUM

Wekan < 9.35 cloneBoard - Private Board Information Disclosure

Title source: manual
STIX 2.1

Description

Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-862
Status published
Products (1)
wekan/wekan < 9.35
Published Jul 15, 2026
Tracked Since Jul 16, 2026