WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier.
Metrics
Affected Vendors & Products
References
History
Sat, 07 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier. | |
| Title | WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorId | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-07T21:58:53.680Z
Reserved: 2026-02-02T20:12:33.397Z
Link: CVE-2026-25567
No data.
Status : Received
Published: 2026-02-07T22:16:02.333
Modified: 2026-02-07T22:16:02.333
Link: CVE-2026-25567
No data.
OpenCVE Enrichment
No data.