Impact
Vikunja before version 2.6.0 allows a read‑only user to retrieve a link‑share hash from single‑share read endpoints. The retrieved hash can be swapped for a link‑share JWT that grants higher privileges, enabling unauthorized writes or administrative actions. The vulnerability corresponds to CWE‑200, exposing sensitive information that allows privilege escalation.
Affected Systems
Vikunja from the vendor go‑vikunja is affected. All releases prior to 2.6.0 are vulnerable. The issue is present in any installation of Vikunja where the single‑share read endpoint is exposed to read‑only members.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers only require access to a link‑share read endpoint as a read‑only member; the share hash can then be used to obtain a higher‑privilege JWT. Because any authenticated read‑only user can retrieve the hash, the risk to all users of vulnerable installations is considerable. Exploitation is straightforward and can lead to full administrative control over the affected account or system.
OpenCVE Enrichment