CVE Explorer
CVE-2026-59154
Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists and ChecklistItems because updates are authorized only against the current source doc.cardId and do not inspect the destination cardId or boardId in the update modifier, allowing a low-privileged authenticated user with write access to one board and knowledge of a target private card id to create checklist data on an accessible card
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"wekan","vendor":"wekan","versions":[{"status":"affected","version":"< 9.64"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d038e97640d69fc0a4b85696ae7d633944cb4590a5119d45f9a03bd8bd894d3b · sha256:ec8a46e89df226af… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d038e97640d69fc0a4b85696ae7d633944cb4590a5119d45f9a03bd8bd894d3b · sha256:ec8a46e89df226af… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d038e97640d69fc0a4b85696ae7d633944cb4590a5119d45f9a03bd8bd894d3b · sha256:ec8a46e89df226af… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/wekan/wekan/commit/b1ca76007b9a295fd029dfefc1a2d1d6f1920835","tags":["x_refsource_MISC"],"url":"https://github.com/wekan/wekan/commit/b1ca76007b9a295fd029dfefc1a2d1d6f1920835"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d038e97640d69fc0a4b85696ae7d633944cb4590a5119d45f9a03bd8bd894d3b · sha256:ec8a46e89df226af… · /containers/cna/references/1
{"name":"https://github.com/wekan/wekan/releases/tag/v9.64","tags":["x_refsource_MISC"],"url":"https://github.com/wekan/wekan/releases/tag/v9.64"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d038e97640d69fc0a4b85696ae7d633944cb4590a5119d45f9a03bd8bd894d3b · sha256:ec8a46e89df226af… · /containers/cna/references/2
{"name":"https://github.com/wekan/wekan/security/advisories/GHSA-gv8h-5p3p-6hx7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/wekan/wekan/security/advisories/GHSA-gv8h-5p3p-6hx7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d038e97640d69fc0a4b85696ae7d633944cb4590a5119d45f9a03bd8bd894d3b · sha256:ec8a46e89df226af… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.