Skip to content
Threat Feed

Vendor

Vikunja

5 briefs RSS
high advisory

Principal-Type Confusion Vulnerability in Vikunja

Vikunja versions up to 2.4.0 are vulnerable to authorization bypass via principal-type confusion, allowing attackers with a valid link-share JWT to manipulate team rosters and bot users.

Vikunja web-vulnerability authorization-bypass cve-2026-76216
1t 1c
critical advisory

Authorization Flaws in Vikunja Expose Share Hashes and Allow Attachment Manipulation

Authorization flaws in Vikunja before version 2.2.1 allow authenticated users with read access to escalate privileges by obtaining admin-level share hashes via the LinkSharing.ReadAll endpoint, and also permit instance-wide data exfiltration and destruction by manipulating task attachments through an Insecure Direct Object Reference (IDOR) vulnerability in the GetTaskAttachment endpoint.

Vikunja authorization-bypass idor data-exfiltration data-destruction web-application cve
3t 1c
critical advisory

Vikunja Unauthenticated Instance-Wide Data Breach via Link Share and IDOR

Chained authorization flaws in Vikunja allow an unauthenticated attacker to download and delete all file attachments across all projects by disclosing share hashes and exploiting cross-project attachment access.

Vikunja idor privilege-escalation data-breach
2r 6t
high advisory

Vikunja TOTP Two-Factor Authentication Bypass via OIDC Login

Vikunja version 2.2.2 and earlier has a two-factor authentication bypass vulnerability via the OIDC login path, where TOTP enrollment is ignored when a local user with TOTP enabled is matched via OIDC email fallback, allowing attackers with a matching email address in the OIDC provider to gain access without the second factor.

Vikunja totp oidc bypass cve-2026-34727
2r 1t 3i
high advisory

Vikunja Link Share Hash Disclosure Leads to Privilege Escalation

The Vikunja application is vulnerable to privilege escalation, where the LinkSharing.ReadAll() method permits authenticated users to list all link shares, including secret hashes, without proper authorization checks, allowing an attacker with a read-only link share to escalate to full admin access.

Vikunja privilege-escalation credential-access
2r 2t