Skip to content
Threat Feed

Vendor

Vikunja

7 briefs RSS
high advisory

Unauthenticated Rate Limiting Vulnerability in Vikunja Authentication Endpoints

Vikunja versions before 2.6.0 lack rate limiting on public /api/v2 authentication endpoints, enabling credential stuffing, account enumeration, and password-reset flooding.

Vikunja
1r 1t 1c
critical advisory

Path Traversal Vulnerability in Marker Upload Handler (CVE-2026-85684)

An unauthenticated path traversal vulnerability in the marker library up to version 2.0.0 allows attackers to overwrite or delete arbitrary files on the system by manipulating the file.filename parameter.

marker
1r 1t 1c
high advisory

Vikunja Improper Authorization via ProjectView Deletion

An improper authorization vulnerability in Vikunja allows authenticated users to destroy task organization data in other projects by supplying a target view ID within a crafted API request.

Vikunja authorization-bypass web-application data-destruction
2t
critical advisory

Authorization Flaws in Vikunja Expose Share Hashes and Allow Attachment Manipulation

Authorization flaws in Vikunja before version 2.2.1 allow authenticated users with read access to escalate privileges by obtaining admin-level share hashes via the LinkSharing.ReadAll endpoint, and also permit instance-wide data exfiltration and destruction by manipulating task attachments through an Insecure Direct Object Reference (IDOR) vulnerability in the GetTaskAttachment endpoint.

Vikunja authorization-bypass idor data-exfiltration data-destruction web-application cve
3t 1c
critical advisory

Vikunja Unauthenticated Instance-Wide Data Breach via Link Share and IDOR

Chained authorization flaws in Vikunja allow an unauthenticated attacker to download and delete all file attachments across all projects by disclosing share hashes and exploiting cross-project attachment access.

Vikunja idor privilege-escalation data-breach
2r 6t
high advisory

Vikunja TOTP Two-Factor Authentication Bypass via OIDC Login

Vikunja version 2.2.2 and earlier has a two-factor authentication bypass vulnerability via the OIDC login path, where TOTP enrollment is ignored when a local user with TOTP enabled is matched via OIDC email fallback, allowing attackers with a matching email address in the OIDC provider to gain access without the second factor.

Vikunja totp oidc bypass cve-2026-34727
2r 1t 3i
high advisory

Vikunja Link Share Hash Disclosure Leads to Privilege Escalation

The Vikunja application is vulnerable to privilege escalation, where the LinkSharing.ReadAll() method permits authenticated users to list all link shares, including secret hashes, without proper authorization checks, allowing an attacker with a read-only link share to escalate to full admin access.

Vikunja privilege-escalation credential-access
2r 2t