CVE-2026-68559: Wekan

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the asynchronous exporterExcel.canExport(user) authorization guard from models/server/ExporterExcel.js without awaiting it. The returned Promise was always truthy, so exporterExcel.build(res) ran even when board.isVisibleBy(user) would deny access, allowing any authenticated non-member to download private board card titles, descriptions, lists, swimlanes, members, and metadata. This issue is fixed in version 9.74.

Affected products

  • Wekan Wekan: from 9.57, before 9.74 (fixed in 9.74)

Published 2026-08-19. Last modified 2026-09-09.