CVE-2026-52893
Wekan, an open‑source kanban tool, had a flaw that let attackers hijack user accounts via OpenID Connect. By using an OIDC account that shares a victim’s email or username, an attacker could merge their credentials into the victim’s account and then log in as that user. The problem is fixed in Wekan 9.32.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Wekan versions prior to 9.32. Typical users are teams and individuals who use Wekan for project management.
Real-world impact
An attacker could take over any Wekan account whose email or username matches an OIDC account they control, gaining full access to that user’s boards and data.
Why this severity
The CVSS score of 9.2 reflects that the vulnerability is exploitable over the network with low effort, requires no user interaction, and gives an attacker high impact on confidentiality and integrity of the victim’s data.
What to do about it
- 01Upgrade Wekan to version 9.32 or later.
- 02Restart the Wekan service.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 18d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 18, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.