CVE-2026-53447
MEDIUMWekan < 9.35 cloneBoard - Private Board Information Disclosure
Title source: manualDescription
Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/wekan/wekan/security/advisories/GHSA-qfqv-42qw-vvwh
X_Refsource_Misc x_refsource_misc
https://github.com/wekan/wekan/commit/357de728c03113b787065bac2c5832ad77f1a117
X_Refsource_Misc x_refsource_misc
https://github.com/wekan/wekan/releases/tag/v9.35
Scores
CVSS v3
6.5
EPSS
0.0023
EPSS Percentile
14.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
CWE-862
Status
published
Products (1)
wekan/wekan
< 9.35
Published
Jul 15, 2026
Tracked Since
Jul 16, 2026