CVE-2026-1892 | WeKan up to 8.20 REST API models/boards.js setBoardOrgs item.cardId/item.checklistId/card.boardId improper authorization (EUVD-2026-5322)
A vulnerability was found in WeKan up to 8.20 and classified as critical. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improper authorization.
This vulnerability is traded as CVE-2026-1892. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.