PT-2026-27454 · Vikunja · Vikunja

Kolaente

·

Publicado

2026-03-24

·

Atualizado

2026-03-27

·

CVE-2026-33700

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.2.1
Description Vikunja is a self-hosted task management platform. A flaw exists where the DELETE /api/v1/projects/:project/shares/:share endpoint does not confirm that the link share belongs to the project specified in the URL. An attacker with administrator privileges for any project can delete link shares from other projects by using their own project ID along with the target share ID.
Recommendations Update to version 2.2.1 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33700
GHSA-F95F-77JX-FCJC
GO-2026-4850
SUSE-SU-2026:1135-1

Produtos afetados

Vikunja