Description
vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Team Enumeration
Action: Patch
AI Analysis

Impact

The vulnerability stems from insufficient validation of team membership when a project is shared. Authorized users can supply arbitrary team identifiers to the project teams endpoint and retrieve the complete roster for that team, including member names and administrator status. This flaw allows an attacker to infer the existence of all teams and their composition, thereby compromising confidentiality and potentially facilitating further social engineering or privilege escalation.

Affected Systems

The impact applies to the open‑source project management application "vikunja" from the vendor go‑vikunja. All releases prior to version 2.6.0 are affected, as they lack the access checks that restrict team enumeration based on project permissions.

Risk and Exploitability

The assigned CVSS score of 5.3 reflects a moderate risk; the EPSS score of < 1% indicates a low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must first authenticate to the system, but once authenticated they can repeatedly query the endpoint to enumerate any team. Because the exploitation does not require advanced privileges or complex payloads, the likelihood of real‑world abuse is moderate, especially in organizations where many teams are defined.

Generated by OpenCVE AI on September 20, 2026 at 16:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vikunja to version 2.6.0 or later, which implements proper validation of team access when attaching teams to projects.
  • If a quick upgrade is not possible, disable or restrict access to the project teams API for users who are not intended to view team membership, and monitor logs for abnormal enumeration attempts.
  • After applying the fix or temporary controls, audit team rosters to confirm that no unauthorized team data is exposed and remove any inadvertent cross‑team shares.

Generated by OpenCVE AI on September 20, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams.
Title vikunja before 2.6.0 Team Enumeration via Project Share
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-200
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:03:30.623Z

Reserved: 2026-09-15T11:10:41.353Z

Link: CVE-2026-91980

cve-icon Vulnrichment

Updated: 2026-09-15T16:03:26.911Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:54.940

Modified: 2026-09-16T19:49:18.987

Link: CVE-2026-91980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor