PT-2026-60321 · Wekan · Wekan

CVE-2026-53445

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wekan versions prior to 9.32
Description The copyBoard Meteor DDP method in server/publications/boards.js allows an authenticated user to copy a private board without verifying the this.userId, membership, or admin access. This allows unauthorized users to duplicate private boards, including their cards, checklists, custom fields, labels, and rules. In contrast, the REST endpoint '/api/boards/:boardId/copy' correctly implements admin access checks.
Recommendations Update to version 9.32.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53445
GHSA-7W2H-G83C-JQRP

Affected Products

Wekan