CVE-2026-1962 is a critical improper access control vulnerability affecting WeKan versions up to 8.20, specifically within the attachment migration function in server/attachmentMigration.js. This flaw allows remote attackers to gain full control over confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8 (CRITICAL). While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 95/100 underscores its potential severity. Organizations using affected WeKan versions are strongly advised to upgrade to version 8.21 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.21CPE matchmatch criteria | cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.