PT-2026-109320 · Vikunja · Vikunja

CVE-2026-57458

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vikunja version 2.3.0
Description An authentication-context mismatch allows a scoped API token limited to the oauth.authorize permission to bypass its declared restrictions. By calling the 'POST /api/v1/oauth/authorize' endpoint, an attacker can obtain an OAuth authorization code and subsequently exchange it at the 'POST /api/v1/oauth/token' endpoint for a standard bearer JSON Web Token (JWT) and refresh token. These resulting credentials are not bound by the original API token's permissions, granting unauthorized access to routes outside the original scope for the same user, such as 'GET /api/v1/user' and 'GET /api/v1/projects'.
Recommendations Update Vikunja to version 2.4.0.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57458
GHSA-V3P6-34MC-HJ7V

Affected Products

Vikunja