PT-2026-92097 · Vikunja · Vikunja

CVE-2026-91983

·

Published

2026-09-15

·

Updated

2026-10-09

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.6.0
Description An API token scope bypass exists in task read endpoints because the authorization process does not inspect query string parameters. An attacker with limited token scopes can utilize the expand parameter to access restricted data, including comments, reactions, and time entries, bypassing proper permission verification.
Recommendations Update to version 2.6.0 or later. As a temporary mitigation, restrict the use of the expand parameter in task read endpoints.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91983
GHSA-9RG3-V78M-26Q8
GHSA-PHPH-C358-5MWM

Affected Products

Vikunja