Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41454

29
FAUCET Score

WeKan versions prior to 8.35 contain a missing authorization vulnerability in the Integration REST API endpoints that fails to properly verify user privileges. This allows authenticated board members to perform administrative actions beyond their authorized scope, including enumerating webhook URLs, creating, modifying, or deleting integrations, and managing integration activities. The vulnerability exists in the JsonRoutes REST handlers due to insufficient authorization checks. The vulnerability carries a CVSS score of 8.3 (HIGH) with a network attack vector requiring only low complexity and low privileges. An authenticated attacker needs no user interaction to exploit this issue, resulting in high confidentiality and integrity impact with limited availability impact. The attack surface is non-localized, affecting the entire system scope. There is currently no evidence of active exploitation in the wild, as this CVE does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on threat tracking lists. The EPSS score of 0.00036 indicates this vulnerability is less likely to be exploited compared to most other CVEs. Organizations running WeKan should prioritize updating to version 8.35 or later, though immediate threat level appears moderate based on exploitation indicators.

Impacted Technologies

VendorProductVersion(s)CPE
WekanWekan
>= 0, < 8.35.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 7th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / wekan/wekan/commit/2cd702f48df2b8aef0e7381685f8e089986a18a4
github.com / wekan/wekan/releases/tag/v8.35
vulncheck.com / advisories/wekan-missing-authorization-via-integration-rest-api