{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vikunja-api--1.0.0--2.3.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vikunja:api:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91985"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vikunja API (\u003c= 2.5.0)","Vikunja API (\u003e= 1.0.0, \u003c= 2.3.0)","Vikunja API (= 2.3.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","access-control","web-application","authentication-bypass","oidc","identity-takeover","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Vikunja"],"content_html":"\u003cp\u003eVikunja API versions up to and including 2.5.0 contain a broken access control vulnerability (CVE-2026-91985) that allows authenticated read-only project members to escalate privileges. The vulnerability exists in the single-share read endpoints for both v1 and v2 APIs. While these endpoints properly restrict access based on project read permissions, they incorrectly include the share's internal \u003ccode\u003ehash\u003c/code\u003e field in the response.\u003c/p\u003e\n\u003cp\u003eThis \u003ccode\u003ehash\u003c/code\u003e is a bearer credential that can be used against the unauthenticated \u003ccode\u003ePOST /shares/{share}/auth\u003c/code\u003e endpoint to obtain a JWT associated with the share's specific permission level (e.g., read-write or admin). Because these share IDs are small sequential integers, a read-only member can identify and query existing shares, extract the hashes, and generate tokens that bypass project-level member restrictions. This effectively allows an attacker to perform write or administrative actions for which they are not authorized, exceeding their intended read-only role.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker is granted read-only access to a project by an owner.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates available link shares for the project by guessing sequential share IDs.\u003c/li\u003e\n\u003cli\u003eAttacker sends an authenticated GET request to \u003ccode\u003e/api/v1/projects/{project}/shares/{share}\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application returns the full share object, including the sensitive \u003ccode\u003ehash\u003c/code\u003e field, despite the attacker only having read-only permissions.\u003c/li\u003e\n\u003cli\u003eAttacker submits the intercepted \u003ccode\u003ehash\u003c/code\u003e to the unauthenticated \u003ccode\u003ePOST /api/v1/shares/{hash}/auth\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe server validates the hash and returns a valid link-share JWT with the share's defined permission level (e.g., read-write).\u003c/li\u003e\n\u003cli\u003eAttacker uses the generated link-share JWT to perform unauthorized write operations against the project, bypassing their own user-level 403 restriction.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in unauthorized privilege escalation and information exposure (CWE-862, CWE-639, CWE-200). A read-only member can escalate their access to the level of any existing link share. If an admin-level link share exists, the attacker can manage project settings and other shares, even if they remain restricted from general user management. This compromises the integrity of project data and the security model of shared workspaces.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Vikunja API to the latest version (patch for CVE-2026-91985). If immediate patching is not possible, restrict the creation of link shares with elevated permissions for projects containing untrusted or read-only members. Detection teams should monitor for anomalous usage of link-share authentication endpoints or unusual patterns of access to share-read APIs by standard users.\u003c/p\u003e\n","date_modified":"2026-10-09T21:25:51Z","date_published":"2026-10-09T21:25:02Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vikunja-privilege-escalation/","summary":"A broken access control vulnerability in Vikunja allows read-only project members to retrieve sensitive link-share hashes and escalate their privileges to the permission level of those shares.","title":"Vikunja Broken Access Control and Privilege Escalation via Link Share","url":"https://feed.craftedsignal.io/briefs/2026-10-vikunja-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Vikunja API (\u003e= 1.0.0, \u003c= 2.3.0)","version":"https://jsonfeed.org/version/1.1"}