Description
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Vikunja before version 2.6.0 allows a read‑only user to retrieve a link‑share hash from single‑share read endpoints. The retrieved hash can be swapped for a link‑share JWT that grants higher privileges, enabling unauthorized writes or administrative actions. The vulnerability corresponds to CWE‑200, exposing sensitive information that allows privilege escalation.

Affected Systems

Vikunja from the vendor go‑vikunja is affected. All releases prior to 2.6.0 are vulnerable. The issue is present in any installation of Vikunja where the single‑share read endpoint is exposed to read‑only members.

Risk and Exploitability

The CVSS score is 8.7, indicating high severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers only require access to a link‑share read endpoint as a read‑only member; the share hash can then be used to obtain a higher‑privilege JWT. Because any authenticated read‑only user can retrieve the hash, the risk to all users of vulnerable installations is considerable. Exploitation is straightforward and can lead to full administrative control over the affected account or system.

Generated by OpenCVE AI on September 20, 2026 at 16:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Vikunja to version 2.6.0 or later to apply the fix that restricts access to the link‑share hash field.
  • If an upgrade cannot be performed immediately, limit or disable the link‑sharing feature for read‑only users until the patch is deployed.
  • Monitor application logs for unexpected link‑share JWT exchanges or unauthorized write attempts, and review user permissions to detect potential privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.
Title Vikunja before 2.6.0 Privilege Escalation via Link Share Hash
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-200
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:04:15.007Z

Reserved: 2026-09-15T11:10:41.354Z

Link: CVE-2026-91985

cve-icon Vulnrichment

Updated: 2026-09-15T16:03:58.847Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:57.010

Modified: 2026-09-16T19:49:18.987

Link: CVE-2026-91985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor