A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. Patch name: 545566f5663545d16174e0f2399f231aa693ab6e. It is advisable to upgrade the affected component.
{
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "8.0"
},
{
"last_affected": "8.0"
},
{
"introduced": "8.1"
},
{
"last_affected": "8.1"
},
{
"introduced": "8.2"
},
{
"last_affected": "8.2"
},
{
"introduced": "8.3"
},
{
"last_affected": "8.3"
},
{
"introduced": "8.4"
},
{
"last_affected": "8.4"
},
{
"introduced": "8.5"
},
{
"last_affected": "8.5"
},
{
"introduced": "8.6"
},
{
"last_affected": "8.6"
},
{
"introduced": "8.7"
},
{
"last_affected": "8.7"
},
{
"introduced": "8.8"
},
{
"last_affected": "8.8"
},
{
"introduced": "8.9"
},
{
"last_affected": "8.9"
},
{
"introduced": "8.13"
},
{
"last_affected": "8.13"
}
]
}
],
"cwe_ids": [
"CWE-266",
"CWE-284"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1964.json",
"cna_assigner": "VulDB"
}{
"cpe": "cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.21"
}
]
}