Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2026-55652

Wekan, an open‑source kanban tool built with Meteor, had a flaw in versions before 9.46. The bug let attackers send a forged X‑Forwarded‑For header and a HEADER_LOGIN_ID for any user, causing the system to issue a valid login token without authentication. The issue is fixed in Wekan 9.46.

publishedJul 16, 2026
last modifiedJul 17, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
28th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 18, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Wekan users running any version earlier than 9.46, especially administrators who rely on the header‑login feature.

02

Real-world impact

An attacker could impersonate any user, including administrators, gaining full access to boards, data, and administrative controls without needing a password.

03

Why this severity

The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely over the network, requires no user interaction, and grants complete confidentiality, integrity, and availability compromise for the affected system.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade Wekan to version 9.46 or later.
  2. 02Restart the Wekan service to apply the update.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 16, 2026 · 18d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 19, 2026 · 15d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →