Логотип exploitDog
bind:CVE-2026-25568
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-25568

Количество 3

Количество 3

nvd логотип

CVE-2026-25568

около 2 месяцев назад

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-25568

около 2 месяцев назад

WeKan versions prior to 8.19 contain an authorization logic vulnerabil ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-mxjf-259r-3r76

около 2 месяцев назад

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-25568

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-25568

WeKan versions prior to 8.19 contain an authorization logic vulnerabil ...

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-mxjf-259r-3r76

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу