PT-2026-60319 · Wekan · Wekan
CVE-2026-52893
·
Published
2026-07-15
·
Updated
2026-07-16
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wekan versions prior to 9.32
Description
The
Accounts.onCreateUser function in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing user without verifying ownership or checking the email verified status. An attacker can use an OIDC provider account with a victim's email or username to merge their credentials into the victim's account and gain unauthorized access.Recommendations
Update to version 9.32.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wekan