PT-2026-109321 · Vikunja · Vikunja

CVE-2026-62367

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v4.0

7.5

High

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Vikunja versions 1.0.0 through 2.3.0
Description When an administrator enables the per-provider emailfallback option on an OpenID Connect provider, the software links an SSO login to a pre-existing local account using only the email claim from the Identity Provider (IdP). The system fails to verify the email verified signal (or Microsoft xms edov) and does not require the local account password. This allows an attacker who can obtain a token from the configured issuer containing a victim's email to gain full session access to that victim's local account without any interaction or consent from the user. This issue specifically affects local accounts that do not have TOTP (Time-based One-Time Password) enabled, as TOTP acts as a gate for those users.
Recommendations Update to version 2.4.0. As a temporary mitigation, disable the emailfallback option for OpenID Connect providers, especially those that are untrusted or allow users to set their own email addresses without verification.

Fix

Insufficient Verification of Data Authenticity

Authentication Bypass by Spoofing

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62367
GHSA-XV7Q-FVMC-JX96

Affected Products

Vikunja