CVE-2026-30845 describes a sensitive information disclosure vulnerability in Wekan, an open-source kanban tool, affecting versions 8.31.0 through 8.33. The flaw allows any board member, including read-only users, and even unauthenticated clients for public boards, to access webhook URLs and authentication tokens due to insufficient field filtering in board publications. This medium-severity vulnerability (CVSS 6.9) has a low attack complexity and could lead to unauthorized actions in connected external services. While there is no known active exploitation or public exploit code, the issue has garnered some community discussion and media coverage, indicating awareness. A fix is available in Wekan version 8.34.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.31, < 8.33CPE matchmatch criteria | cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.