← volver
CVE-2026-2209

WeKan Custom Translation translationBody.js setCreateTranslation improper authorization

CVSS 5.3 MEDIUMEPSS 0.2%CWE-266CWE-285
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
08 feb 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can be launched remotely. Upgrading to version 8.19 is sufficient to fix this issue. The patch is identified as f244a43771f6ebf40218b83b9f46dba6b940d7de. It is suggested to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Productos afectados
n/a · WeKan

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →