PT-2026-92099 · Vikunja · Vikunja

·

CVE-2026-91985

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.6.0
Description Insufficient access restriction to the link-share hash field in single-share read endpoints allows read-only members to obtain the secret credential of a share. An attacker can use this disclosed hash to obtain a link-share JWT (JSON Web Token), which is a compact, URL-safe means of representing claims to be transferred between two parties. This allows the attacker to escalate privileges and perform unauthorized administrative actions or writes.
Recommendations Update to version 2.6.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91985
GHSA-QFWC-VX6F-3G6G

Affected Products

Vikunja