CVE-2026-25560 | WeKan up to 8.18 ldap.js ldap injection (EUVD-2026-5712)
A vulnerability was found in WeKan up to 8.18. It has been declared as critical. Impacted is an unknown function of the file packages/wekan-ldap/server/ldap.js. The manipulation results in ldap injection.
This vulnerability is known as CVE-2026-25560. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.