PT-2026-60320 · Wekan · Wekan
CVE-2026-53444
·
Published
2026-07-15
·
Updated
2026-07-16
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wekan versions prior to 9.32
Description
OIDC-related Meteor methods in
packages/wekan-oidc/oidc server.js, server/models/org.js, and server/models/team.js are globally callable without the required admin authorization checks. Authenticated users can execute the functions setCreateOrgFromOidc(), setOrgAllFieldsFromOidc(), setCreateTeamFromOidc(), setTeamAllFieldsFromOidc(), boardRoutineOnLogin(), or groupRoutineOnLogin() to create or modify organizations and teams. Additionally, the groupRoutineOnLogin() function can be used to grant global admin privileges when the PROPAGATE OIDC DATA variable is enabled.Recommendations
Update to version 9.32.
Exploit
Fix
Missing Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wekan