PT-2026-109321 · Vikunja · Vikunja
CVE-2026-62367
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v4.0
7.5
High
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Vikunja versions 1.0.0 through 2.3.0
Description
When an administrator enables the per-provider
emailfallback option on an OpenID Connect provider, the software links an SSO login to a pre-existing local account using only the email claim from the Identity Provider (IdP). The system fails to verify the email verified signal (or Microsoft xms edov) and does not require the local account password. This allows an attacker who can obtain a token from the configured issuer containing a victim's email to gain full session access to that victim's local account without any interaction or consent from the user. This issue specifically affects local accounts that do not have TOTP (Time-based One-Time Password) enabled, as TOTP acts as a gate for those users.Recommendations
Update to version 2.4.0.
As a temporary mitigation, disable the
emailfallback option for OpenID Connect providers, especially those that are untrusted or allow users to set their own email addresses without verification.Fix
Insufficient Verification of Data Authenticity
Authentication Bypass by Spoofing
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vikunja