What is CVE-2026-68559?
Wekan open-source kanban versions 9.57-9.74 have a vulnerability in the /api/boards/:boardId/exportExcel route where the authorization guard is called without 'await', returning an unchecked Promise. This allows unauthenticated users to export board data as Excel files. Upgrade to the latest version to mitigate the issue.
Azərbaycanca: Wekan açıq mənbəli kanban tətbiqinin 9.57-9.74 versiyalarında /api/boards/:boardId/exportExcel API marşrutunda "await" olmadan icazə yoxlaması (Promise) çağırıldığı üçün autentifikasiya yan keçilə bilər. Bu səbəbdən təsdiqlənməmiş istifadəçilər board məlumatlarını Excel formatında ixrac edə bilər. Tətbiqi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Wekan are affected by the authentication bypass vulnerability in CVE-2026-68559?
The vulnerability affects Wekan open-source kanban versions 9.57 through 9.74.
What can an unauthenticated user do by exploiting CVE-2026-68559?
An unauthenticated user can export board data as Excel files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.