Description
Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

Vikunja versions prior to 2.6.0 fail to verify that the project_view_id supplied in task-position requests actually belongs to the same project as the task. Because the project_view_id is supplied by the attacker, the vulnerability is a CWE‑639 type of authorization bypass. An authenticated attacker can send POST or PUT requests to the task‑position endpoint, inserting or altering rows that associate tenant. This enables unauthorized modification of project views and can expose sensitive data across tenant boundaries.

Affected Systems

The flaw affects all deployments of Vikunja running any release before 2.6.0. No other vendors, products, or versions are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 and EPSS score of less than 1% indicate a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The attack requires that the attacker be authenticated to the instance, so the vector is internal. Once authenticated, the attacker can exploit the missing project_view_id validation to add or modify task positions in views that belong to other tenants, potentially leaking or corrupting data.

Generated by OpenCVE AI on September 20, 2026 at 16:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vikunja to version 2.6.0 or later to apply the authoritative fix.
  • Restrict or block non‑admin users from accessing the POST and PUT /task‑position API endpoints through a firewall or API gateway until the upgrade is completed.
  • Review user roles and permissions to ensure that only authorized personnel have rights to modify task positions or project views; perform an audit of existing privileges and remove excess permissions.

Generated by OpenCVE AI on September 20, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.
Title Vikunja before 2.6.0 Broken Object-Level Authorization via task-position
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-639
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:27:58.744Z

Reserved: 2026-09-15T11:10:41.354Z

Link: CVE-2026-91984

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:27.824Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:55.903

Modified: 2026-09-17T20:18:54.770

Link: CVE-2026-91984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key