CVE-2026-41454
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
22/04/2026
Last modified:
23/04/2026
Description
WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.30
Severity 3.x
HIGH



