Wekan Privilege Escalation Vulnerability Allowing Unauthorized Access to Teams and Organizations

Vulnerability

A vulnerability in Wekan, an open-source kanban board system, allows authenticated users to manipulate their entire user document, including sensitive fields such as organizations, teams, and login status. This issue arises from inadequate server-side authorization, enabling privilege escalation and unauthorized access to other teams or organizations. The vulnerability affects Wekan versions prior to 18.15 and was addressed in version 18.16.

Impact

Exploitation of this vulnerability could lead to unauthorized access to boards of any organizations or teams, allowing users to view or interact with content they should not have access to.

Reproduction

To reproduce this vulnerability, an authenticated user can send a request to update their user document. The request can include modifications to sensitive fields such as 'orgs', 'teams', and 'loginDisabled'. Since the update is processed without proper authorization checks, this can result in unauthorized changes and access.

Remediation

Users are advised to update to Wekan version 18.16 or later, where this vulnerability has been fixed.

Added: Dec 15, 2025, 2:22 PM
Updated: Dec 15, 2025, 6:56 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
6.3
remediation
7.7
relevance
1.4
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.