PT-2026-60319 · Wekan · Wekan

CVE-2026-52893

·

Published

2026-07-15

·

Updated

2026-07-16

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wekan versions prior to 9.32
Description The Accounts.onCreateUser function in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing user without verifying ownership or checking the email verified status. An attacker can use an OIDC provider account with a victim's email or username to merge their credentials into the victim's account and gain unauthorized access.
Recommendations Update to version 9.32.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52893
GHSA-MP7G-HJ5Q-GXHQ

Affected Products

Wekan