VulnerabilityAnalyzed
CVE-2026-1962
A vulnerability has been found in WeKan up to 8.20.
MEDIUM 5.3EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be initiated remotely. Upgrading to version 8.21 is sufficient to resolve this issue. The identifier of the patch is 053bf1dfb76ef230db162c64a6ed50ebedf67eee. It is recommended to upgrade the affected component.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-284
- Affected
- wekan project/wekan
- Source
- cna@vuldb.com
References
- https://github.com/wekan/wekan/Product
- https://github.com/wekan/wekan/commit/053bf1dfb76ef230db162c64a6ed50ebedf67eeePatch
- https://github.com/wekan/wekan/releases/tag/v8.21Product, Release Notes
- https://vuldb.com/?ctiid.344484Permissions Required, VDB Entry
- https://vuldb.com/?id.344484Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.742677Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.