← Volver a CVEs
CVE-2026-1896
MEDIUM6.3
Descripcion
A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation of the argument boardId leads to improper access controls. The attack is possible to be carried out remotely. Upgrading to version 8.21 addresses this issue. The identifier of the patch is cc35dafef57ef6e44a514a523f9a8d891e74ad8f. Upgrading the affected component is advised.
Detalles CVE
Puntuacion CVSS v3.16.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado2/5/2026
Ultima modificacion2/10/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
wekan_project:wekan
Debilidades (CWE)
CWE-266CWE-284
Referencias
https://github.com/wekan/wekan/(cna@vuldb.com)
https://github.com/wekan/wekan/releases/tag/v8.21(cna@vuldb.com)
https://vuldb.com/?ctiid.344268(cna@vuldb.com)
https://vuldb.com/?id.344268(cna@vuldb.com)
https://vuldb.com/?submit.742670(cna@vuldb.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.