CVE-2026-25561 | WeKan up to 8.18 Attachment Upload API attachmentApi.js authorization (EUVD-2026-5711)
A vulnerability was found in WeKan up to 8.18. It has been rated as critical. The affected element is an unknown function of the file server/routes/attachmentApi.js of the component Attachment Upload API. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-25561. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.