Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41454

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

EPSS

Процентиль: 20%
0.00274
Низкий

8.3 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.3
debian
4 месяца назад

WeKan before8.35 contains a missing authorization vulnerability in the ...

CVSS3: 8.3
github
4 месяца назад

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

EPSS

Процентиль: 20%
0.00274
Низкий

8.3 High

CVSS3

Дефекты

CWE-862