CVE-2026-1962Disclosure(wekan_project / wekan)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be initiated remotely. Upgrading to version 8.21 is sufficient to resolve this issue. The identifier of the patch is 053bf1dfb76ef230db162c64a6ed50ebedf67eee. It is recommended to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wekan

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
wekan

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-05: 1Mentions · 2026-02-06: 1Technical Details · 2026-02-06: 102-0502-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1962 A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Mi… https://www.cve.org/CVERecord?id=CVE-2026-1962

    Post summary

    A new CVE-2026-1962 vulnerability has been reported in WeKan up to version 8.20, affecting an unspecified function in attachmentMigration.js, with no additional details or PoC disclosed.

    00010224
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1962 WeKan Attachment Migration Remote Improper Access Control Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1962

    Post summary

    A new CVE (CVE-2026-1962) is announced for WeKan's attachment migration, describing a remote improper access control flaw, but no further details on exploitation or mitigation are provided.

    0000068
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwekan_projectwekan---

Explore more