
CVE-2026-25567 WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request bo… https://www.cve.org/CVERecord?id=CVE-2026-25567
Post summary
The text discloses an IDOR vulnerability (CVE-2026-25567) affecting WeKan versions prior to 8.19, detailing how the comment creation API accepts an authorId.
