Description
Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker with a limited API token to request additional data through the expand query parameter in task read endpoints. The authorization logic does not validate the token scope for expanded fields, enabling access to comments, reactions, and time entries that the token normally should not reveal. This flaw results in data exposure of sensitive task details without requiring elevated privileges.

Affected Systems

Vikunja, versions prior to 2.6.0 (go‑vikunja:vikunja).

Risk and Exploitability

The flaw has a CVSS score of 5.3, indicating moderate severity. The EPSS score of < 1% reflects a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers must possess a valid API token with limited scope but can manipulate the expand parameter to bypass scope restrictions. This bypass does not grant new privileges or authentication, but it does expose otherwise protected data such as task comments, reactions, and time entries. The attack vector is through standard API calls to task read endpoints, which is likely exploitable by anyone who can interact with the API using an authorized token.

Generated by OpenCVE AI on September 20, 2026 at 16:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vikunja to version 2.6.0 or later, which fixes the token scope validation for expand parameters.
  • If an upgrade is delayed, configure API token scopes to restrict access to only the necessary fields and disable unused expand options in the application settings.
  • Monitor API activity for unexpected usage of the expand parameter and audit tokens for over‑privileged scopes.

Generated by OpenCVE AI on September 20, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.
Title Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-863
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:52:07.941Z

Reserved: 2026-09-15T11:10:41.353Z

Link: CVE-2026-91983

cve-icon Vulnrichment

Updated: 2026-09-15T15:52:03.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:55.373

Modified: 2026-09-16T20:16:09.343

Link: CVE-2026-91983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses