{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/vikunja-0.22.0-through-2.3.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-68581"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vikunja (0.22.0 through 2.3.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Vikunja"],"content_html":"\u003cp\u003eVikunja versions 0.22.0 through 2.3.0 are affected by a flaw in API token management where the application fails to validate the principal type during ID resolution. The vulnerability stems from the use of a generic web.Auth.GetID() interface that treats user IDs and link-share IDs as identical numeric sequences. An authenticated attacker can identify a target user's numeric ID and repeatedly create link shares on a project they control until the link-share identifier increments to match the target's user ID. By generating a JWT for this specific link share, the attacker can successfully impersonate the target user when accessing the /api/v1/tokens endpoints. This allows the attacker to list, delete, or create new API tokens with arbitrary scopes under the victim's identity. This vulnerability was addressed in Vikunja version 2.4.0.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Vikunja instance with a standard low-privilege account.\u003c/li\u003e\n\u003cli\u003eAttacker performs an authenticated user search to enumerate and capture the target's numeric user ID.\u003c/li\u003e\n\u003cli\u003eAttacker accesses a project they have write access to and creates multiple link shares.\u003c/li\u003e\n\u003cli\u003eAttacker monitors the link-share incrementing sequence until the ID matches the target user's numeric ID.\u003c/li\u003e\n\u003cli\u003eAttacker generates a JWT associated with the specific malicious link share.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP request to the /api/v1/tokens endpoint using the link-share JWT.\u003c/li\u003e\n\u003cli\u003eThe application incorrectly resolves the JWT principal as the target user.\u003c/li\u003e\n\u003cli\u003eAttacker successfully creates or deletes API tokens on behalf of the target user to achieve persistence or exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for complete account takeover of API token management. An attacker can create new API tokens with escalated permissions, effectively gaining long-term programmatic access to the victim's data, tasks, and integrations. This vulnerability impacts any organization using Vikunja for sensitive project management or internal task tracking.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Vikunja to version 2.4.0 or higher immediately to apply the fix for CVE-2026-68581.\u003c/li\u003e\n\u003cli\u003eReview application logs for unusual spikes in link-share creation activity, which may indicate an attacker attempting to brute-force the numeric ID sequence.\u003c/li\u003e\n\u003cli\u003eAudit existing API tokens for any unexpected tokens created by users, particularly those with administrative or broad read/write scopes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-02T13:36:25Z","date_published":"2026-08-02T13:36:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-vikunja-auth-bypass/","summary":"Vikunja versions 0.22.0 through 2.3.0 contain an authentication bypass vulnerability allowing attackers to impersonate users and manage their API tokens via manipulated link-share JWTs.","title":"Authentication Bypass and Privilege Escalation in Vikunja API","url":"https://feed.craftedsignal.io/briefs/2026-08-vikunja-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Vikunja (0.22.0 Through 2.3.0)","version":"https://jsonfeed.org/version/1.1"}