PT-2026-27451 · Vikunja · Vikunja

Restriction

·

Publicado

2026-03-24

·

Atualizado

2026-03-27

·

CVE-2026-33678

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.2.1
Description Vikunja is a self-hosted task management platform. A flaw exists where the TaskAttachment.ReadOne() function queries attachments using only the ID, disregarding the task ID from the URL. The permission check in CanRead() verifies access to the task in the URL, but ReadOne() can load attachments from other tasks. This allows authenticated users to potentially download or delete any attachment by manipulating the task ID. Attachment IDs are sequential integers, simplifying the process of identifying them. The function TaskAttachment.ReadOne() is vulnerable.
Recommendations Update to version 2.2.1 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33678
GHSA-JFMM-MJCP-8WQ2
GO-2026-4853
SUSE-SU-2026:1135-1

Produtos afetados

Vikunja