CVE-2026-30846Disclosure(wekan_project / wekan)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing any authentication check on the server side. Although the subscription is normally invoked from the admin settings page, the server-side publication has no access control, meaning any DDP client, including unauthenticated ones, can subscribe and receive the data. This allows an unauthenticated attacker to retrieve global webhook URLs and authentication tokens, potentially enabling unauthorized use of those webhooks and access to connected external services. This issue has been fixed in version 8.34.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wekan

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
wekan

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-06: 2Technical Details · 2026-03-06: 203-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30846 Unauthenticated Global Webhook Exposure in Wekan Versions... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30846 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A newly disclosed vulnerability (CVE‑2026‑30846) in Wekan allows unauthenticated access to global webhooks. No proof‑of‑concept, exploit, patch, or active exploitation information is included.

    0000045
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30846 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—includi… https://www.cve.org/CVERecord?id=CVE-2026-30846

    Post summary

    The text is a disclosure of CVE-2026-30846, noting that Wekan’s globalwebhooks publication accidentally exposes all global webhook integrations in versions 8.31.0–8.33.

    0000085
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwekan_projectwekan---

Explore more