Description
Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote authentication bypass via CalDAV BasicAuth
Action: Apply Patch
AI Analysis

Impact

Vikunja versions earlier than 2.6.0 are vulnerable to an authentication bypass that allows an unauthenticated attacker to perform unlimited credential-guessing against the CalDAV BasicAuth endpoints. The flaw, a CWE-307 weakness involving authentication bypass, arises because the /dav, /.well-known, and /feeds routes lack proper rate limiting, enabling an attacker to overwhelm the anti-brute-force controls and gain access to account passwords. This directly results in full compromise of password-only accounts, providing the attacker with unauthorized access to the instance and any data stored therein.

Affected Systems

All instances running Vikunja prior to version 2.6.0 are affected. The Vulnerability originates from the Vikunja project (go-vikunja:vikunja) and includes the CalDAV BasicAuth functionality exposed by the application.

Risk and Exploitability

The CVSS v3.1 score of 8.7 classifies this flaw as high severity. While the EPSS score is reported as < 1%, indicating a low but nonzero exploitation probability, the lack of rate limiting provides a workable opportunity for attackers. The vulnerability is not listed in the CISA KEV catalog. Attackers can send repetitive unauthenticated requests to the specified CalDAV endpoints to bypass anti-brute-force mechanisms and fully compromise accounts.

Generated by OpenCVE AI on September 20, 2026 at 16:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vikunja to version 2.6.0 or later so that authentication is properly enforced and rate limiting is implemented.
  • If upgrading is not immediately possible, disable CalDAV BasicAuth or configure a strong rate-limiting policy on the /dav, /.well-known, and /feeds routes to halt credential-guessing attempts.
  • Deploy monitoring on authentication logs to detect repeated failed attempts and block offending IP addresses, thereby reducing the window of opportunistic exploitation.

Generated by OpenCVE AI on September 20, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.
Title Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-307
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:55:04.161Z

Reserved: 2026-09-15T11:09:54.873Z

Link: CVE-2026-91973

cve-icon Vulnrichment

Updated: 2026-09-15T15:54:38.336Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:54.230

Modified: 2026-09-16T20:16:09.343

Link: CVE-2026-91973

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts