HomeCVE Intelligence › CVE-2026-55234
CVSS 9.8 CRITICAL Vulnerability

CVE-2026-55234: Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rule…

Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored so…

9.8CVSS Score
CRITICALSeverity
NOCISA KEV
0.2%EPSS Score
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-55234
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeVulnerability
CVSS Score9.8 (CRITICAL)
EPSS Score0.2% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update modifier. Any authenticated user with write access to their own board can call /cards/update, /lists/update, or /swimlanes/update to move cards, lists, or swimlanes into a private board they are not a member of. This issue is fixed in version 9.37.

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-55234","confidence_score":23.5,"first_seen":"2026-07-18","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-55234 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence