Description
Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Local Account Takeover via OIDC Email Fallback
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to sign in as a legitimate local user by providing an OIDC token contains the target’s email address. Because the system never checks whether the email has been verified or requires the user’s password, any token from the configured provider can be used to hijack the session and obtain full access to the victim’s data. The flaw effectively grants full read/write privileges to the account holder without the victim’s consent.

Affected Systems

The issue affects Vikunja, the open‑source self‑hosted task management platform, in versions 1.0.0 through 2.3.0. The vendor is Go‑Vikunja and the product is Vikunja. The fix is included in release 2.4.0.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is considered a high risk. Exploitation does not rely on local access or password disclosure; an adversary only needs a valid token for the victim’s email, which can be acquired via phishing, compromised IdP credentials, or a legitimately signed token. The EPSS score is not available, but the absence of email verification makes this a serious threat. The vulnerability is not listed in CISA KEV at the time of writing.

Generated by OpenCVE AI on October 9, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vikunja to version 2.4.0 or later, which removes the email‑fallback flaw.
  • If upgrading immediately is not possible, disable the per‑provider emailfallback option or enforce email_verified (or the Microsoft xms_edov) check before account linkage.
  • After applying the fix, review IdP token issuance policies and rotate any compromised credentials or revoke tokens that could be used to target user emails.

Generated by OpenCVE AI on October 9, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xv7q-fvmc-jx96 Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover
History

Fri, 09 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Fri, 09 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue.
Title Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover
Weaknesses CWE-287
CWE-290
CWE-345
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:49:08.891Z

Reserved: 2026-07-13T22:04:59.677Z

Link: CVE-2026-62367

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:05.470

Modified: 2026-10-09T21:17:05.470

Link: CVE-2026-62367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T22:30:13Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-345

    Insufficient Verification of Data Authenticity