PT-2026-92097 · Vikunja · Vikunja
CVE-2026-91983
·
Published
2026-09-15
·
Updated
2026-10-09
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vikunja versions prior to 2.6.0
Description
An API token scope bypass exists in task read endpoints because the authorization process does not inspect query string parameters. An attacker with limited token scopes can utilize the
expand parameter to access restricted data, including comments, reactions, and time entries, bypassing proper permission verification.Recommendations
Update to version 2.6.0 or later.
As a temporary mitigation, restrict the use of the
expand parameter in task read endpoints.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vikunja