PT-2026-27454 · Vikunja · Vikunja

·

CVE-2026-33700

·

Published

2026-03-24

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.2.1
Description Vikunja is a self-hosted task management platform. A flaw exists where the DELETE /api/v1/projects/:project/shares/:share endpoint does not confirm that the link share belongs to the project specified in the URL. An attacker with administrator privileges for any project can delete link shares from other projects by using their own project ID along with the target share ID.
Recommendations Update to version 2.2.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33700
GHSA-F95F-77JX-FCJC
GO-2026-4850
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Vikunja