Description
Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a valid access token can read the secret, import it into their own authenticator, and generate valid codes indefinitely to defeat the second factor and enable account takeover.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypass Two‑Factor Authentication
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker who possesses a valid access token to read the raw TOTP shared secret through the /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode GET endpoints. By retrieving this secret they can import it into an authenticator app and generate valid codes indefinitely, effectively defeating the second factor and permitting account takeover. The weakness is a credential exposure flaw (CWE‑522).

Affected Systems

The affected product is Vikunja, any release before version 2.6.0. Vendors and product families are listed as "go-vikunja:vikunja" using the CPE cpe::vikunja:*:*:*:*:*:*:*.*

Risk and Exploitability

The CVSS score is 5.3, indicating moderate risk. The EPSS score is < 1%, pointing to a very low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. An attacker with a valid access token can issue a simple HTTP GET request to the /api/v1/user/settings/totp or /api/v1/user/settings/totp/qrcode endpoint to retrieve the raw TOTP shared secret. With that they can import it into an authenticator and generate valid MFA codes indefinitely, thereby bypassing two‑factor authentication and enabling account takeover.

Generated by OpenCVE AI on September 20, 2026 at 16:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Vikunja release after 2.6.0 to remove the exposed TOTP endpoints
  • If an update cannot be performed immediately, revoke existing user access tokens and issue new ones to limit the window of vulnerability
  • Consider configuring the system to require re‑authentication or token rotation before granting access to TOTP data, thereby mitigating the risk of secret disclosure

Generated by OpenCVE AI on September 20, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a valid access token can read the secret, import it into their own authenticator, and generate valid codes indefinitely to defeat the second factor and enable account takeover.
Title Vikunja before 2.6.0 TOTP Secret Disclosure via API
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-522
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:14:33.105Z

Reserved: 2026-09-15T11:10:41.353Z

Link: CVE-2026-91982

cve-icon Vulnrichment

Updated: 2026-09-17T15:13:57.801Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:55.227

Modified: 2026-09-17T16:18:32.237

Link: CVE-2026-91982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials