CVE-2026-52891
Wekan, an open‑source Kanban board built with Meteor, had a critical flaw in versions before 9.07. The avatar upload feature embedded user‑supplied filenames into a shell command used for MIME‑type detection, allowing attackers to inject shell metacharacters and run arbitrary commands on the server. The issue is fixed in Wekan 9.07 and later.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Wekan versions earlier than 9.07, typically small teams and organizations using the open‑source Kanban tool.
Real-world impact
An attacker could execute any command on the server, potentially taking full control, exfiltrating data, installing malware, or disrupting services.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability allows remote code execution with low attack complexity, requires low privileges, no user interaction, and compromises confidentiality, integrity, and availability of the entire system.
What to do about it
- 01Upgrade Wekan to version 9.07 or later.
- 02Restart the Wekan service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 18d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.