Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026
Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops)
CVE-2026-52892
Description
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating custom-field routes. A read-only board member can call POST, PUT, and DELETE handlers for /api/boards/:boardId/custom-fields and custom-field dropdown items to create, update, or delete board custom fields. This issue is fixed in version 9.32.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/wekan/wekan/commit/70db04a93fedabe40331f21f86e6bdc91625914emitrex_refsource_MISC
- github.com/wekan/wekan/releases/tag/v9.32mitrex_refsource_MISC
- github.com/wekan/wekan/security/advisories/GHSA-6733-4wgq-8xvrmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.