PT-2026-60320 · Wekan · Wekan

CVE-2026-53444

·

Published

2026-07-15

·

Updated

2026-07-16

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wekan versions prior to 9.32
Description OIDC-related Meteor methods in packages/wekan-oidc/oidc server.js, server/models/org.js, and server/models/team.js are globally callable without the required admin authorization checks. Authenticated users can execute the functions setCreateOrgFromOidc(), setOrgAllFieldsFromOidc(), setCreateTeamFromOidc(), setTeamAllFieldsFromOidc(), boardRoutineOnLogin(), or groupRoutineOnLogin() to create or modify organizations and teams. Additionally, the groupRoutineOnLogin() function can be used to grant global admin privileges when the PROPAGATE OIDC DATA variable is enabled.
Recommendations Update to version 9.32.

Exploit

Fix

Missing Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53444
GHSA-CV95-8H7C-2FFQ

Affected Products

Wekan