CVE-2026-25859: Wekan Project Wekan
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.
Affected products
- Wekan Project Wekan: before 8.20 (fixed in 8.20)
Published 2026-02-07. Last modified 2026-07-14.