PT-2026-60327 · Wekan · Wekan

CVE-2026-55652

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wekan versions prior to 9.46
Description The header-login feature, when configured with HEADER LOGIN TRUSTED IPS, improperly uses the getRequestIp() function in server/lib/headerLoginAuth.js. This allows the system to trust the client-supplied X-Forwarded-For header over the actual socket address. Consequently, an unauthenticated attacker can provide a HEADER LOGIN ID for any username to obtain a meteor login token session, which can grant unauthorized access to any account, including the administrator.
Recommendations Update to version 9.46. As a temporary mitigation, avoid using the HEADER LOGIN TRUSTED IPS configuration until the update is applied.

Exploit

Fix

Improper Authentication

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55652
GHSA-JGGC-QVFC-JR6X

Affected Products

Wekan