Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-41454

4 месяца назад

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

CVSS3: 8.3
EPSS: Низкий
debian логотип

CVE-2026-41454

4 месяца назад

WeKan before8.35 contains a missing authorization vulnerability in the ...

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-f2hf-mr43-85mv

4 месяца назад

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-41454

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

CVSS3: 8.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-41454

WeKan before8.35 contains a missing authorization vulnerability in the ...

CVSS3: 8.3
0%
Низкий
4 месяца назад
github логотип
GHSA-f2hf-mr43-85mv

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

CVSS3: 8.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу