WeKan < 8.35 Missing Authorization via Integration REST API
Published Apr 22, 2026
8.7
HIGHCVSS 4.0
EPSS 0.48%
Description
WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.
Affected products
-
- Version 0StatusaffectedConstraints<8.35.0
- Version
-
- Version StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 23, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.48% (0.00480) | 39.16th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.27% (0.00274) | 18.93th | v5 (v2026.06.15) |
| Apr 23, 2026 | 0.04% (0.00036) | 10.71th | v4 (v2025.03.14) |
References (3)
- https://github.com/wekan/wekan/commit/2cd702f48df2b8aef0e7381685f8e089986a18a4 patch
- https://github.com/wekan/wekan/releases/tag/v8.35 release-notes
- https://www.vulncheck.com/advisories/wekan-missing-authorization-via-integration-rest-api third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/wekan/wekan/commit/2cd702f48df2b8aef0e7381685f8e089986a18a4 | patch | |
| https://github.com/wekan/wekan/releases/tag/v8.35 | release-notes | |
| https://www.vulncheck.com/advisories/wekan-missing-authorization-via-integration-rest-api | third-party-advisory |
Change history (0)
No recorded changes yet.