โ† All reports

Wekan versions before 8.35 have critical security vulnerabilities that allow unauthorized administrative actions and server-side request forgery.

CybersecurityTechnologyConflictApr 23, 2026score 0.174 posts ยท 0 replies across 1 instances
This thread discusses multiple security vulnerabilities in WeKan versions before 8.35, including missing authorization and server-side request forgery issues, highlighting the need for urgent patches.

Claims

Wekan versions before 8.35 have critical security vulnerabilities that allow unauthorized administrative actions and server-side request forgery.
Parent: CybersecurityEntity: WekanImpact: negativeDate: Apr 23, 2026Target: Wekan versions before 8.35 have critical security vulnerabilities that allow unauthorized administrative actions and server-side request forgery.

Source posts

@[email protected]
๐ŸŸ  CVE-2026-41454 - High (8.3) WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integr... ๐Ÿ”— https://www.thehackerwire.com/vulnerability/CVE-2026-41454/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
@[email protected]
๐ŸŸ  CVE-2026-41455 - High (8.5) WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the url schema field accepts any string without protocol restriction or destination validation. Attackers who can create or modify in... ๐Ÿ”— https://www.thehackerwire.com/vulnerability/CVE-2026-41455/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
@[email protected]
๐Ÿšจ EUVD-2026-25117 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Wekan, Wekan ๐Ÿข Vendor: WeKan ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations in... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25117 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25118 ๐Ÿ“Š Score: 6.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Wekan, Wekan ๐Ÿข Vendor: WeKan ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the url schema field accepts any string without protocol restriction or destination validation. Attackers who can create or modify integration... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25118 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability