CVE-2026-25567 | WeKan up to 8.18 Card Comment Creation API models/cardComments.js authorization (EUVD-2026-5705)
A vulnerability described as problematic has been identified in WeKan up to 8.18. Affected by this vulnerability is an unknown functionality of the file models/cardComments.js of the component Card Comment Creation API. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-25567. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.