CVE-2026-25566 | WeKan up to 8.18 Card Move models/cards.js authorization (EUVD-2026-5706)
A vulnerability marked as critical has been reported in WeKan up to 8.18. Affected is an unknown function of the file models/cards.js of the component Card Move Handler. The manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2026-25566. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.