PT-2026-109320 · Vikunja · Vikunja
CVE-2026-57458
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vikunja version 2.3.0
Description
An authentication-context mismatch allows a scoped API token limited to the
oauth.authorize permission to bypass its declared restrictions. By calling the 'POST /api/v1/oauth/authorize' endpoint, an attacker can obtain an OAuth authorization code and subsequently exchange it at the 'POST /api/v1/oauth/token' endpoint for a standard bearer JSON Web Token (JWT) and refresh token. These resulting credentials are not bound by the original API token's permissions, granting unauthorized access to routes outside the original scope for the same user, such as 'GET /api/v1/user' and 'GET /api/v1/projects'.Recommendations
Update Vikunja to version 2.4.0.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vikunja