CVE-2026-25560
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
07/02/2026
Last modified:
10/02/2026
Description
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:* | 8.19 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



