CVE-2026-53447: Wekan
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.
Affected products
- Wekan Wekan: before 9.35 (fixed in 9.35)
Published 2026-07-15. Last modified 2026-07-16.