PT-2026-60327 · Wekan · Wekan
CVE-2026-55652
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wekan versions prior to 9.46
Description
The header-login feature, when configured with
HEADER LOGIN TRUSTED IPS, improperly uses the getRequestIp() function in server/lib/headerLoginAuth.js. This allows the system to trust the client-supplied X-Forwarded-For header over the actual socket address. Consequently, an unauthenticated attacker can provide a HEADER LOGIN ID for any username to obtain a meteor login token session, which can grant unauthorized access to any account, including the administrator.Recommendations
Update to version 9.46.
As a temporary mitigation, avoid using the
HEADER LOGIN TRUSTED IPS configuration until the update is applied.Exploit
Fix
Improper Authentication
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wekan