CVE-2026-59154Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists and ChecklistItems because updates are authorized only against the current source doc.cardId and do not inspect the destination cardId or boardId in the update modifier, allowing a low-privileged authenticated user with write access to one board and knowledge of a target private card id to create checklist data on an accessible card and move it into a private board where they are not a member. This issue is fixed in version 9.64.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2Technical Details · 2026-07-10: 207-10
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59154 Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists … https://www.cve.org/CVERecord?id=CVE-2026-59154 ----- Traducción: CVE-2026-59154 Wek… http://infoflow.cloud`

    Post summary

    CVE‑2026‑59154 reveals a cross‑board authorization bypass in Wekan's Meteor collection allow rules before version 9.64.

    0000035
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-59154 Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists … https://www.cve.org/CVERecord?id=CVE-2026-59154

    Post summary

    The post announces CVE‑2026‑59154—a cross-board authorization bypass in Wekan’s Meteor collection rules—and provides basic technical details but no evidence of active exploitation, PoC, or patch information.

    00000702
    57.8K followersView on X

Explore more