WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.
History

Sat, 07 Feb 2026 22:00:00 +0000

Type Values Removed Values Added
Description WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.
Title WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-07T21:59:13.959Z

Reserved: 2026-02-02T20:12:33.397Z

Link: CVE-2026-25568

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-07T22:16:02.467

Modified: 2026-02-07T22:16:02.467

Link: CVE-2026-25568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.