CVE-2026-1964: Wekan Project Wekan
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. Patch name: 545566f5663545d16174e0f2399f231aa693ab6e. It is advisable to upgrade the affected component.
Affected products
- Wekan Project Wekan: before 8.21 (fixed in 8.21)
Published 2026-02-05. Last modified 2026-06-17.