Vendor
high
advisory
WeKan Missing Authorization Vulnerability in Integration REST API
2 rules 1 TTP 1 CVE 4 IOCsWeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints, allowing authenticated board members to perform administrative actions without proper privilege verification, potentially leading to unauthorized data access and modification.
WeKan
missing-authorization
rest-api
privilege-escalation
2r
1t
1c
4i
high
advisory
WeKan SSRF Vulnerability in Webhook Integration
2 rules 1 TTP 1 CVEWeKan before 8.35 is vulnerable to server-side request forgery (SSRF), allowing attackers with integration modification privileges to set webhook URLs to internal network addresses, leading to unauthorized HTTP POST requests and potential comment manipulation.
WeKan
ssrf
cve-2026-41455
2r
1t
1c