WeKan versions prior to 8.35 contain a missing authorization vulnerability in the Integration REST API endpoints that fails to properly verify user privileges. This allows authenticated board members to perform administrative actions beyond their authorized scope, including enumerating webhook URLs, creating, modifying, or deleting integrations, and managing integration activities. The vulnerability exists in the JsonRoutes REST handlers due to insufficient authorization checks. The vulnerability carries a CVSS score of 8.3 (HIGH) with a network attack vector requiring only low complexity and low privileges. An authenticated attacker needs no user interaction to exploit this issue, resulting in high confidentiality and integrity impact with limited availability impact. The attack surface is non-localized, affecting the entire system scope. There is currently no evidence of active exploitation in the wild, as this CVE does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on threat tracking lists. The EPSS score of 0.00036 indicates this vulnerability is less likely to be exploited compared to most other CVEs. Organizations running WeKan should prioritize updating to version 8.35 or later, though immediate threat level appears moderate based on exploitation indicators.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wekan | Wekan | >= 0, < 8.35.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.