Back

HIGH

WeKan < 8.35 Missing Authorization via Integration REST API

Published Apr 22, 2026

Description

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 22, 2026
Updated Jul 14, 2026
Reserved Apr 20, 2026
CISA Vulnrichment
Updated Apr 23, 2026
NVD
Status Deferred
Modified Jul 14, 2026
Red Hat
Severity n/a
Public date n/a