Description
Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure – User Enumeration
Action: Apply Patch
AI Analysis

Impact

Vikunja before 2.6.0 fails to properly validate link‑share tokens in its v2 API user‑search endpoints. When an attacker has a read‑only share link, the projects endpoint returns all users with access to the shared project, and an attacker can then query the global search endpoint with the same token to confirm whether a specific username exists. This allows enumeration of active users on the instance, exposing sensitive user data solely through publicly available API calls.

Affected Systems

The vulnerability affects the open‑source project management application Vikunja, distributed by go‑vikunja. All releases prior to version 2.6.0 are vulnerable. The flaw is specific to the v2 API user‑search endpoints and applies to any instance that has share links enabled.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. The EPSS score of < 1% indicates a low probability of exploitation at present. Since the flaw relies on a read‑only share link, which may be freely available on public projects, the attacker can discover user enumerations by accessing the public API endpoints. The likely attack vector is the public API using a malicious request with a discovered share‑link token, which allows enumeration of usernames. The vulnerability is not listed in CISA's KEV catalog, so widespread exploitation is not currently documented, but the moderate CVSS score and the ease of using share links make it a potential risk for organizations that publicly share projects.

Generated by OpenCVE AI on September 20, 2026 at 16:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Vikunja version 2.6.0 or later.
  • Revoke or delete existing read‑only share links that are no longer needed.
  • Restrict use of the global search endpoint or monitor traffic for enumeration patterns.

Generated by OpenCVE AI on September 20, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint.
Title Vikunja before 2.6.0 User Enumeration via v2 API
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-200
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T18:47:28.550Z

Reserved: 2026-09-15T11:10:41.353Z

Link: CVE-2026-91981

cve-icon Vulnrichment

Updated: 2026-09-21T18:47:02.775Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:55.087

Modified: 2026-09-21T19:17:16.220

Link: CVE-2026-91981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor