CVE-2026-2209

A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can be launched remotely. Upgrading to version 8.19 is sufficient to fix this issue. The patch is identified as f244a43771f6ebf40218b83b9f46dba6b940d7de. It is suggested to upgrade the affected component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:*

History

11 Feb 2026, 18:56

Type Values Removed Values Added
References () https://github.com/wekan/wekan/ - () https://github.com/wekan/wekan/ - Product
References () https://github.com/wekan/wekan/commit/f244a43771f6ebf40218b83b9f46dba6b940d7de - () https://github.com/wekan/wekan/commit/f244a43771f6ebf40218b83b9f46dba6b940d7de - Patch
References () https://github.com/wekan/wekan/releases/tag/v8.19 - () https://github.com/wekan/wekan/releases/tag/v8.19 - Product, Release Notes
References () https://vuldb.com/?ctiid.344923 - () https://vuldb.com/?ctiid.344923 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.344923 - () https://vuldb.com/?id.344923 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.752269 - () https://vuldb.com/?submit.752269 - Third Party Advisory, VDB Entry
First Time Wekan Project wekan
Wekan Project
CPE cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*:*

08 Feb 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-08 02:15

Updated : 2026-02-11 18:56


NVD link : CVE-2026-2209

Mitre link : CVE-2026-2209

CVE.ORG link : CVE-2026-2209


JSON object : View

Products Affected

wekan_project

  • wekan
CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization