Skip to main content
EPSS 0.3%top 81%

CVE-2026-68582: Authorization Bypass Through User-Controlled Key in go-vikunja vikunja

0
Critical
Published: 08/02/2026 (08/02/2026, 12:15:28 UTC)
Source: CVE Database V5
Vendor/Project: go-vikunja
Product: vikunja

Description

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. For a link-share token holder, the task scope is pinned to the share's own project, but the view is taken from the attacker-controlled path and never re-validated. As a result, a holder of any project share link can read any other tenant's kanban bucket records — bucket titles and the full created_by user object (username, name, id) — for every view in the instance. The same missing pre-authorization view load also creates a project/view-ID existence oracle (404 vs. non-404) usable by link shares and ordinary authenticated users. Task contents remain constrained to the share's own project and are not disclosed. Fixed in 2.4.0.

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

go-vikunja

vikunja

Affected versions
>=0.24.0 <2.4.0
github.com/go-vikunja/vikunja
pkg:golang/github.com/go-vikunja/vikunja
Affected versions
=0.24.0<=2.3.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/09/2026, 14:15:41 UTC

Technical Analysis

The vulnerability in Vikunja (CVE-2026-68582) affects versions >=0.24.0 and <=2.3.0. The task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks) loads the requested project view from the URL path without verifying authorization. While link-share tokens restrict task scope to their own project, the view parameter is attacker-controlled and not re-validated, allowing unauthorized reading of other tenants' kanban bucket titles and full created_by user objects (username, name, id). Additionally, the missing pre-authorization check creates a project/view-ID existence oracle via differing 404 responses. Task contents themselves are not disclosed. The issue was fixed in version 2.4.0.

Potential Impact

An attacker with any project share link can access sensitive metadata from other tenants, including kanban bucket titles and user identity information, across all views in the instance. This leads to unauthorized information disclosure. However, actual task content remains protected and is not exposed. The vulnerability also allows attackers to confirm the existence of project/view IDs, which could aid further reconnaissance.

Mitigation Recommendations

A fix is available in Vikunja version 2.4.0. Users should upgrade to version 2.4.0 or later to remediate this vulnerability. No vendor advisory is provided here, so patch status is based on the description stating the issue is fixed in 2.4.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-07-31T11:56:29.760Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a6f3c9fbf32cb7a348adf7b

Added to database: 08/02/2026, 12:48:31 UTC

Last enriched: 08/09/2026, 14:15:41 UTC

Last updated: 09/15/2026, 10:01:34 UTC

Views: 117

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses