What is CVE-2026-68558?
CVE-2026-68558 is a critical flaw in Wekan open-source kanban. From versions 8.36 to 9.74, the outgoing webhook URL validator only checks the hostname literally, allowing DNS names like `nip.io` to bypass filters and access internal resources. Users must update to the latest version immediately.
Azərbaycanca: CVE-2026-68558 Wekan açıq mənbəli kanban tətbiqində aşkarlanmış kritik zəiflikdir. 8.36-dan 9.74-ə qədər versiyalarda outgoing webhook URL validator səhvən yalnız hostname-i yoxlayır, `nip.io` kimi DNS adları ilə daxili resurslara giriş imkanı yaradır. İstifadəçilər dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Wekan are affected by CVE-2026-68558?
The CVE-2026-68558 vulnerability affects Wekan open-source kanban from versions 8.36 to 9.74.
How to protect against CVE-2026-68558?
Users must update Wekan to the latest version immediately to protect against CVE-2026-68558.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.