{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vikunja-2.4.0-and-earlier/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-76216"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vikunja (2.4.0 and earlier)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","authorization-bypass","cve-2026-76216"],"_cs_type":"advisory","_cs_vendors":["Vikunja"],"content_html":"\u003cp\u003eVikunja versions through 2.4.0 contain a critical principal-type confusion vulnerability (CVE-2026-76216) stemming from missing type guards in internal permission checks. The vulnerability occurs because the application treats 'LinkSharing' principals with ID N identically to 'user' principals with users.id == N. Because the application uses an autoincrementing ID system, an attacker possessing a valid link-share JWT can exploit ID collisions to bypass authorization boundaries.\u003c/p\u003e\n\u003cp\u003eBy successfully exploiting this confusion, an unauthorized actor can perform privileged administrative actions, including removing victims from teams, enumerating and deleting bot users, or exfiltrating sensitive team roster information. This vulnerability is classified under CWE-639 (Authorization Bypass Through User-Controlled Key) and represents a significant risk to teams relying on Vikunja for sensitive task and project management. Defenders should prioritize patching to version 2.4.1 or later to implement the missing type guard logic.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker obtains or generates a valid link-share JWT for a shared Vikunja resource.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the target user's ID or the ID of a target bot user within the application's autoincrement sequence.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request to the Vikunja API, injecting their link-share JWT.\u003c/li\u003e\n\u003cli\u003eThe request hits one of the three vulnerable permission check endpoints lacking type validation.\u003c/li\u003e\n\u003cli\u003eThe backend application erroneously maps the attacker's 'LinkSharing' principal ID to the target 'user' principal ID due to the lack of type guards.\u003c/li\u003e\n\u003cli\u003eThe application performs authorization logic assuming the attacker is the authenticated user associated with the collided ID.\u003c/li\u003e\n\u003cli\u003eThe attacker executes unauthorized operations, such as deleting a bot user or accessing the team roster.\u003c/li\u003e\n\u003cli\u003eThe final objective is achieved: unauthorized modification of team configurations or exfiltration of roster data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized modification of team structures and data exfiltration. Attackers can specifically remove legitimate team members, delete automation bot users, and access private team rosters. This results in the disruption of project management workflows and potential disclosure of sensitive project data for all organizations utilizing vulnerable versions of Vikunja.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all instances of Vikunja to version 2.4.1 or later immediately to address CVE-2026-76216.\u003c/li\u003e\n\u003cli\u003eAudit application access logs for unusual patterns of API requests originating from JWT-authenticated sessions that involve administrative endpoints (e.g., team membership or user deletion).\u003c/li\u003e\n\u003cli\u003eReview all team rosters for unauthorized modifications or missing bot users that may indicate past exploitation.\u003c/li\u003e\n\u003cli\u003eImplement strict rate limiting on API endpoints to mitigate attempts to brute-force or guess sequential user/principal IDs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T14:34:30Z","date_published":"2026-08-19T14:34:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-vikunja-auth-bypass/","summary":"Vikunja versions up to 2.4.0 are vulnerable to authorization bypass via principal-type confusion, allowing attackers with a valid link-share JWT to manipulate team rosters and bot users.","title":"Principal-Type Confusion Vulnerability in Vikunja","url":"https://feed.craftedsignal.io/briefs/2026-08-vikunja-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Vikunja (2.4.0 and Earlier)","version":"https://jsonfeed.org/version/1.1"}