Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 07 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Description Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.
Title WeKan < 8.20 Migration Functionality Insufficient Permission Checks
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-07T21:59:42.083Z

Reserved: 2026-02-06T19:12:03.463Z

Link: CVE-2026-25859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-07T22:16:02.910

Modified: 2026-02-07T22:16:02.910

Link: CVE-2026-25859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses