Multiple Vulnerabilities Discovered in WeKan Affecting Versions Up to 8.20

Multiple Vulnerabilities Discovered in WeKan Affecting Versions Up to 8.20

First seen 8 Feb 2026, 21:48 UTC Tenable 35.1

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in WeKan versions up to 8.20, impacting the Administrative Repair Handler and Position-History Tracking components. CVE-2026-2206, published on 2026-02-08, involves improper access controls, while CVE-2026-1897, published on 2026-02-05, relates to missing authorization. Both vulnerabilities can be exploited remotely and are resolved by upgrading to version 8.21.

Timeline

2026-02-05
CVE-2026-1897 published
2026-02-08
CVE-2026-2206 published
2026-02-08
Patch for CVE-2026-2206 released
2026-02-08
Advisory to upgrade to version 8.21 issued