HomeCVE Intelligence › CVE-2026-52891
CVSS 9.8 CRITICAL Security Vulnerability

CVE-2026-52891: Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functio…

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avat…

9.8CVSS Score
CRITICALSeverity
NOCISA KEV
0.4%EPSS Score
Security VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-52891
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeSecurity Vulnerability
CVSS Score9.8 (CRITICAL)
EPSS Score0.4% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/fileValidation.js used a shell command with the avatar filename, shell metacharacters such as backticks and $() in the filename could execute commands on the server. This issue is fixed in version 9.07.

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-52891","confidence_score":23.5,"first_seen":"2026-07-18","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-52891 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence