CVE-2026-30846
CVE-2026-30846 is a high-severity vulnerability in Wekan Project Wekan with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v4: 8.7
- EPSS exploit prediction: 0% (28th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-10065
- Weakness: CWE-306
- Affected product: Wekan Project Wekan
- Published:
- Last modified:
Description
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing any authentication check on the server side. Although the subscription is normally invoked from the admin settings page, the server-side publication has no access control, meaning any DDP client, including unauthenticated ones, can subscribe and receive the data. This allows an unauthenticated attacker to retrieve global webhook URLs and authentication tokens, potentially enabling unauthorized use of those webhooks and access to connected external services. This issue has been fixed in version 8.34.
Frequently asked questions
- What is CVE-2026-30846?
- Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing any authentication check on the server side. Although the subscription is normally invoked from the admin settings page, the server-side publication has no access control, meaning any DDP client, including unauthenticated ones, can subscribe and receive the data. This allows an unauthenticated attacker to retrieve global webhook URLs and authentication tokens, potentially enabling unauthorized use of those webhooks and access to connected external services. This issue has been fixed in version 8.34.
- How severe is CVE-2026-30846?
- CVE-2026-30846 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-30846 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (28th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-30846?
- CVE-2026-30846 affects Wekan Project Wekan. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-30846?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-30846 have an EU (EUVD) identifier?
- Yes. CVE-2026-30846 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-10065.
- When was CVE-2026-30846 published?
- CVE-2026-30846 was published on 2026-03-06 and last updated on 2026-06-17.
References
- https://github.com/wekan/wekan/commit/1ee9b2e917104f54c035f6426169a28fedecbdb6
- https://github.com/wekan/wekan/releases/tag/v8.34
- https://securitylab.github.com/advisories/GHSL-2026-037_Wekan/
Affected products (1)
- cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:*
More vulnerabilities in Wekan Project Wekan
- CVE-2026-25560 — Critical (CVSS 9.8): WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied…
- CVE-2026-25859 — High (CVSS 8.8): Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient…
- CVE-2025-65780 — High (CVSS 8.8): An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated…
- CVE-2026-30845 — High (CVSS 8.2): Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication…
- CVE-2025-65781 — High (CVSS 8.2): An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment…
- CVE-2026-30844 — High (CVSS 8.1): Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request…
All CVEs affecting Wekan Project Wekan →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-20357 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team…
- CVE-2026-58115 — Critical (CVSS 10.0): A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running…
- CVE-2026-63508 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to…
- CVE-2026-56163 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to…
- CVE-2026-64812 — Critical (CVSS 10.0): In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- CVE-2026-60644 — Critical (CVSS 10.0): Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →