Impact
The vulnerability allows an attacker who possesses a valid access token to read the raw TOTP shared secret through the /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode GET endpoints. By retrieving this secret they can import it into an authenticator app and generate valid codes indefinitely, effectively defeating the second factor and permitting account takeover. The weakness is a credential exposure flaw (CWE‑522).
Affected Systems
The affected product is Vikunja, any release before version 2.6.0. Vendors and product families are listed as "go-vikunja:vikunja" using the CPE cpe::vikunja:*:*:*:*:*:*:*.*
Risk and Exploitability
The CVSS score is 5.3, indicating moderate risk. The EPSS score is < 1%, pointing to a very low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. An attacker with a valid access token can issue a simple HTTP GET request to the /api/v1/user/settings/totp or /api/v1/user/settings/totp/qrcode endpoint to retrieve the raw TOTP shared secret. With that they can import it into an authenticator and generate valid MFA codes indefinitely, thereby bypassing two‑factor authentication and enabling account takeover.
OpenCVE Enrichment