
CVE-2026-25565 WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write pe… https://www.cve.org/CVERecord?id=CVE-2026-25565
Post summary
The notification discloses a WeKan authorization vulnerability (CVE‑2026‑25565) that allows privilege escalation via improperly validated card update API paths in versions before 8.19.
