VYPR
Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026

Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by ID

CVE-2026-53447

Description

Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.