CVE-2026-55652
Wekan, an open‑source kanban tool built with Meteor, had a flaw in versions before 9.46. The bug let attackers send a forged X‑Forwarded‑For header and a HEADER_LOGIN_ID for any user, causing the system to issue a valid login token without authentication. The issue is fixed in Wekan 9.46.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Wekan users running any version earlier than 9.46, especially administrators who rely on the header‑login feature.
Real-world impact
An attacker could impersonate any user, including administrators, gaining full access to boards, data, and administrative controls without needing a password.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely over the network, requires no user interaction, and grants complete confidentiality, integrity, and availability compromise for the affected system.
What to do about it
- 01Upgrade Wekan to version 9.46 or later.
- 02Restart the Wekan service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 18d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.