Description
Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to 0 to POST /api/v1/projects/{project}. The Project.CanUpdate authorization check in pkg/models/project_permissions.go and UpdateProject logic in pkg/models/project.go only gate nonzero parent values, while UpdateProject always persists parent_project_id, so the explicit zero value bypasses the Admin requirement introduced for CVE-2026-35595. Detachment severs the recursive permission-inheritance chain and can disrupt the owner’s hierarchy and inherited collaborator access. This issue is fixed in version 2.4.0.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Between versions 2.3.0 and 2.4.0, Vikunja allowed a user with Write permissions on a shared child project, but not Admin, to remove that project from its parent hierarchy by sending a POST request to /api/v1/projects/{project} with parent_project_id set to zero. The permission check in Project.CanUpdate only rejects non‑zero parent values while the UpdateProject function writes the parent_project_id regardless of its content, allowing the write‑only user to bypass the intended Admin requirement. The action severs the recursive permission‑inheritance chain, disrupting the owner’s hierarchy and inherited collaborator access, and is identified as a CWE‑862 authorization bypass.

Affected Systems

This weakness exists in the open‑source self‑hosted task management platform Vikunja, implemented in the go‑vikunja:vikunja codebase. All releases from 2.3.0 up through (but not including) 2.4.0 are affected. Any instance running those versions is potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.3 reflects moderate severity, corresponding to an exploit that requires authenticated access with Write permissions on a child project. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting limited documented exploitation. Attackers, however, can trigger this behavior by sending a crafted POST request to the project update endpoint with parent_project_id=0, resulting in unauthorized detachment of the project and loss of inherited permissions. Because the action requires pre‑existing Write access, the risk is mitigated by restricting those permissions; nonetheless, any write‑level user on a shared child project could potentially use this vector.

Generated by OpenCVE AI on August 28, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Vikunja version 2.4.0 or later, which applies the corrected parent_project_id validation.
  • After upgrading, audit child projects to ensure no unauthorized parent associations remain.
  • Review and tighten write‑level permissions on shared projects to limit the ability of ordinary users to modify parent relationships.

Generated by OpenCVE AI on August 28, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-44v6-7fxq-vgf4 Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
History

Fri, 28 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to 0 to POST /api/v1/projects/{project}. The Project.CanUpdate authorization check in pkg/models/project_permissions.go and UpdateProject logic in pkg/models/project.go only gate nonzero parent values, while UpdateProject always persists parent_project_id, so the explicit zero value bypasses the Admin requirement introduced for CVE-2026-35595. Detachment severs the recursive permission-inheritance chain and can disrupt the owner’s hierarchy and inherited collaborator access. This issue is fixed in version 2.4.0.
Title Vikunja incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Go-vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-28T20:29:30.143Z

Reserved: 2026-06-16T14:33:35.710Z

Link: CVE-2026-55064

cve-icon Vulnrichment

Updated: 2026-08-28T20:29:24.515Z

cve-icon NVD

Status : Received

Published: 2026-08-28T20:18:23.613

Modified: 2026-08-28T22:16:50.067

Link: CVE-2026-55064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:45:03Z

Weaknesses