Back

MEDIUM

Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops)

Published Jul 15, 2026

Description

Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating custom-field routes. A read-only board member can call POST, PUT, and DELETE handlers for /api/boards/:boardId/custom-fields and custom-field dropdown items to create, update, or delete board custom fields. This issue is fixed in version 9.32.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 16, 2026
Reserved Jun 8, 2026

CISA Vulnrichment

Updated Jul 16, 2026

NVD

Status Deferred
Modified Jul 16, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 16, 2026

GitHub

No data