
SecEngCyGy@snypet86
Patch
Wekan: unauth admin takeover if header-login SSO is on. CVE-2026-55652 (CVSS 9.8): IP allowlist trusted client X-Forwarded-For to session for any user, incl. admin. Update to 9.46+. Trust XFF only from your reverse proxy. https://github.com/wekan/wekan/security/advisories/GHSA-jggc-qvfc-jr6x #AppSec
Post summary
The advisory discloses a high‑severity unauthenticated admin takeover in Wekan and recommends patching to 9.46+ and restricting X‑Forwarded‑For handling; no evidence of active exploitation or PoC is mentioned.
0000035
23 followersView on X
