These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T20:17:21.567Z and has not been modified since then. The NVD entry is currently 8.7 HIGH. Wekan users and administrators, especially those with deployments using versions prior to 9.90, should be aware of this vulnerability and take necessary actions to mitigate the risk. Affected operators, platf [truncated]
The Wekan open-source kanban built with Meteor had a vulnerability prior to version 9.75, allowing an authenticated user to upload a file with a malicious filename to execute commands as the Wekan server process if an external scanner was configured. This issue was fixed in version 9.75 by adding shellQuote() and passing the file path as a POSIX single-quoted argument. Users of Wekan, especially those wit [truncated]
CVE-2026-55234 is a high-severity vulnerability in Wekan, a Meteor-based open-source kanban platform. An authorization bypass issue allows any authenticated Wekan user with write access to their own board to move cards, lists, or swimlanes into a private board they are not a member of. This issue is fixed in Wekan version 9.37. The vulnerability exists due to insufficient validation of the new boardId in [truncated]
CVE-2026-53447 is a vulnerability in the Wekan open-source kanban built with Meteor. The cloneBoard Meteor method in models/import.js allows an authenticated user to clone a private board into their own account and read its cards, comments, attachments, member information, and activities without proper authorization checks. This issue is fixed in version 9.35. The vulnerability has a CVSS score of 6.5 and [truncated]
CVE-2026-53446 is a MEDIUM severity vulnerability in Wekan, a open-source kanban built with Meteor, affecting versions prior to 9.32. The vulnerability allows a board administrator to configure webhook URLs that cause server-side requests to internal or metadata services due to insufficient validation of user-input URLs in the webhook integration. This issue can lead to potential unauthorized access to in [truncated]
CVE-2026-53445 is a high-severity vulnerability in Wekan, an open-source kanban built with Meteor. Prior to version 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js allows any authenticated user to copy a private board, including its cards, checklists, custom fields, labels, and rules, without checking this.userId, membership, or admin access. The REST POST /api/boards/:boardId [truncated]
CVE-2026-53444 is a high-severity vulnerability in Wekan, an open-source kanban built with Meteor. Prior to version 9.32, Wekan's OIDC-related Meteor methods are globally callable without admin authorization checks. Authenticated users can exploit this issue to create or modify organizations and teams, and even grant global admin privileges when PROPAGATE_OIDC_DATA is enabled. This issue is fixed in versi [truncated]
CVE-2026-52892 debrief: In Wekan, REST handlers for custom fields use insufficient authentication, allowing read-only board members to mutate custom fields. This issue is fixed in version 9.32. The vulnerability class is an authentication bypass, with likely operational impact on board security and data integrity. Source-confidence limits are moderate due to official CVE and NVD confirmation. Review conte [truncated]
CVE-2026-52891 is a critical vulnerability in Wekan's avatar upload feature. Prior to version 9.07, user-supplied filenames were embedded into paths and passed to child_process.exec() for MIME-type detection. This allowed attackers to inject shell metacharacters, such as backticks and $(), to execute commands on the server. The issue was fixed in version 9.07.
CVE-2026-52890 is a high-severity vulnerability in Wekan, a Meteor-based open-source kanban platform. It allows logged-in board members to insert attachments, potentially leading to arbitrary file reads and denial of service through special files like /dev/zero. The issue is fixed in version 9.31. Affected product deployments should be identified, and owners assigned for follow-up. The vulnerability exist [truncated]
A cross-board authorization bypass vulnerability exists in Wekan, a Meteor-based open-source kanban platform. This issue, tracked as CVE-2026-59154, allows a low-privileged authenticated user with write access to one board and knowledge of a target private card ID to create checklist data on an accessible card and move it into a private board where they are not a member. The vulnerability is fixed in Weka [truncated]
CVE-2026-41455 documents a server-side request forgery (SSRF) vulnerability in WeKan versions prior to 8.35, published by NVD on 2026-04-22 and last modified on 2026-05-26. The flaw resides in webhook integration URL handling, where the URL scheme field accepts arbitrary strings without protocol restriction or destination validation. Attackers with permissions to create or modify integrations can configur [truncated]
CVE-2026-41454 is a high-severity vulnerability in Wekan before version 8.35. The issue is a missing authorization vulnerability in the Integration REST API endpoints. This allows authenticated board members to perform administrative actions without proper privilege verification. The vulnerability has a CVSS score of 8.7 and is considered high severity. Affected users should update to version 8.35 or late [truncated]