CVE-2026-1897 describes a missing authorization vulnerability in WeKan versions up to 8.20, specifically within the server/methods/positionHistory.js component. This medium-severity flaw (CVSS 4.3) allows a remote, low-privileged attacker to access unknown functionality, potentially leading to information disclosure. While no public exploits or active exploitation have been observed, and community discussion is minimal, upgrading to WeKan 8.21 is recommended to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.21CPE matchmatch criteria | cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.