Impact
Vikunja versions prior to 2.6.0 fail to enforce rate limiting on public authentication API endpoints such as login, registration, password‑reset, and OAuth token routes. This flaw allows attackers who do not need to authenticate to perform unbounded credential guessing, enumerate accounts, and flood password‑reset requests, potentially compromising accounts and disrupting legitimate password‑reset services.
Affected Systems
The vulnerability affects versions of Vikunja that are prior to 2.6.0, a free and open‑source task‑management platform provided by go‑vikunja.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is considered high severity. The EPSS score of <1% indicates a low likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. Attackers can exploit the lack of throttling from anywhere on the internet, without needing initial access, making the flaw an unauthenticated remote vulnerability that can lead to account compromise.
OpenCVE Enrichment