VulnerabilityAnalyzed
CVE-2026-2208
A security vulnerability has been detected in WeKan up to 8.20.
MEDIUM 5.3EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remotely. Upgrading to version 8.21 is recommended to address this issue. The identifier of the patch is a787bcddf33ca28afb13ff5ea9a4cb92dceac005. The affected component should be upgraded.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862, CWE-863
- Affected
- wekan project/wekan
- Source
- cna@vuldb.com
References
- https://github.com/wekan/wekan/Product
- https://github.com/wekan/wekan/commit/a787bcddf33ca28afb13ff5ea9a4cb92dceac005Patch
- https://github.com/wekan/wekan/releases/tag/v8.21Product, Release Notes
- https://vuldb.com/?ctiid.344922Permissions Required, VDB Entry
- https://vuldb.com/?id.344922Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.752164Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.