CVE-2026-68561

8.8

Wekan · Wekan

Wekan contains an authorization flaw that allows authenticated users to perform unauthorized actions due to improper privilege management.

Executive summary

An authorization vulnerability in Wekan allows authenticated users to escalate privileges and perform unauthorized actions, posing a significant risk to data integrity.

Vulnerability

This is a privilege management and authorization issue (CWE-269, CWE-863) that allows an authenticated user to perform actions outside of their assigned permissions. The flaw occurs within the application logic, enabling users to bypass intended access controls.

Business impact

With a CVSS score of 8.8, this vulnerability presents a critical risk to data confidentiality and integrity. If exploited, an attacker could gain unauthorized administrative access, leading to data exfiltration or the destruction of project management information within the kanban system.

Remediation

Immediate Action: Update the Wekan installation to version 9.89 or later to incorporate the necessary authorization checks.

Proactive Monitoring: Audit user activity logs to identify suspicious escalation events or unauthorized access to sensitive boards and settings.

Compensating Controls: Restrict application access to authorized internal networks using VPNs or IP whitelisting to minimize the attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Security teams should treat this as a high-priority update. Upgrading to version 9.89 is the only effective way to remediate the authorization logic flaw and prevent potential privilege escalation by malicious or compromised accounts.

More Wekan CVEs