Impact
Vikunja versions earlier than 2.6.0 are vulnerable to an authentication bypass that allows an unauthenticated attacker to perform unlimited credential-guessing against the CalDAV BasicAuth endpoints. The flaw, a CWE-307 weakness involving authentication bypass, arises because the /dav, /.well-known, and /feeds routes lack proper rate limiting, enabling an attacker to overwhelm the anti-brute-force controls and gain access to account passwords. This directly results in full compromise of password-only accounts, providing the attacker with unauthorized access to the instance and any data stored therein.
Affected Systems
All instances running Vikunja prior to version 2.6.0 are affected. The Vulnerability originates from the Vikunja project (go-vikunja:vikunja) and includes the CalDAV BasicAuth functionality exposed by the application.
Risk and Exploitability
The CVSS v3.1 score of 8.7 classifies this flaw as high severity. While the EPSS score is reported as < 1%, indicating a low but nonzero exploitation probability, the lack of rate limiting provides a workable opportunity for attackers. The vulnerability is not listed in the CISA KEV catalog. Attackers can send repetitive unauthenticated requests to the specified CalDAV endpoints to bypass anti-brute-force mechanisms and fully compromise accounts.
OpenCVE Enrichment