


Perceptive Security
SOC/SIEM Consultancy

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform admini…
Published:
21 april 2026 om 22:00:00
Alert date:
22 april 2026 om 23:01:43
Source:
nvd.nist.gov
Web Technologies, Identity & Access
WeKan versions before 8.35 contain a missing authorization vulnerability in Integration REST API endpoints. The vulnerability allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can exploit insufficient authorization checks in JsonRoutes REST handlers to enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities. This represents a privilege escalation vulnerability where lower-privileged users can perform administrative functions.
Technical details
Mitigation steps:
Affected products:
WeKan
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41454
https://github.com/wekan/wekan/commit/2cd702f48df2b8aef0e7381685f8e089986a18a4
https://github.com/wekan/wekan/releases/tag/v8.35
https://www.vulncheck.com/advisories/wekan-missing-authorization-via-integration-rest-api
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
