CVE-2026-25859Patch(wekan_project / wekan)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wekan_project wekan systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.

0.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wekan

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
wekan

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-07: 1Patch / Workaround · 2026-02-07: 1Technical Details · 2026-02-07: 102-07
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Patch

    CVE-2026-25859 Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthor… https://www.cve.org/CVERecord?id=CVE-2026-25859

    Post summary

    CVE‑2026‑25859 permits non‑admin users to exploit migration functionality via insufficient permission checks; upgrading to Wekan 8.20 resolves the issue.

    00000189
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwekan_projectwekan---

Explore more