PT-2026-92095 · Vikunja · Vikunja

·

CVE-2026-91981

·

Published

2026-09-15

·

Updated

2026-09-15

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.6.0
Description Improper validation of link-share tokens in the v2 API user search endpoints allows attackers possessing a read-only share link to enumerate project users through the 'projects' endpoint and verify the existence of arbitrary usernames via the global search endpoint.
Recommendations Update to version 2.6.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91981
GHSA-VFXW-3X8P-2VJR

Affected Products

Vikunja