CVE-2026-91980: Exposure of Sensitive Information to an Unauthorized Actor in go-vikunja vikunja
vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams.
AI Analysis
Technical Summary
vikunja before version 2.6.0 fails to validate team access permissions when attaching teams to projects. This allows authenticated users to supply arbitrary team IDs through the project teams API endpoint, enabling them to enumerate all teams and retrieve full team rosters, including member names and administrative status, even for teams they are not authorized to access. This results in exposure of sensitive information to unauthorized actors.
Potential Impact
Authenticated users can enumerate all teams and their members, including unauthorized teams, exposing sensitive information such as member names and admin flags. There is no indication of data modification or denial of service impact. The confidentiality impact is limited to information disclosure.
Mitigation Recommendations
A fix is available in vikunja version 2.6.0. Users should upgrade to version 2.6.0 or later to remediate this vulnerability. No other mitigation guidance is provided or required.
CVE-2026-91980: Exposure of Sensitive Information to an Unauthorized Actor in go-vikunja vikunja
Description
vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams.
CVSS v3.1
Score 4.3medium
Affected software
go-vikunja
vikunja
pkg:golang/github.com/go-vikunja/vikunjaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
vikunja before version 2.6.0 fails to validate team access permissions when attaching teams to projects. This allows authenticated users to supply arbitrary team IDs through the project teams API endpoint, enabling them to enumerate all teams and retrieve full team rosters, including member names and administrative status, even for teams they are not authorized to access. This results in exposure of sensitive information to unauthorized actors.
Potential Impact
Authenticated users can enumerate all teams and their members, including unauthorized teams, exposing sensitive information such as member names and admin flags. There is no indication of data modification or denial of service impact. The confidentiality impact is limited to information disclosure.
Mitigation Recommendations
A fix is available in vikunja version 2.6.0. Users should upgrade to version 2.6.0 or later to remediate this vulnerability. No other mitigation guidance is provided or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-15T11:10:41.353Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa9651c55bf5e2cf502eb28
Added to database: 09/15/2026, 15:32:44 UTC
Last enriched: 09/15/2026, 15:47:29 UTC
Last updated: 09/16/2026, 02:32:35 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.