PT-2026-27451 · Vikunja · Vikunja

·

CVE-2026-33678

·

Published

2026-03-24

·

Updated

2026-03-27

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.2.1
Description Vikunja is a self-hosted task management platform. A flaw exists where the TaskAttachment.ReadOne() function queries attachments using only the ID, disregarding the task ID from the URL. The permission check in CanRead() verifies access to the task in the URL, but ReadOne() can load attachments from other tasks. This allows authenticated users to potentially download or delete any attachment by manipulating the task ID. Attachment IDs are sequential integers, simplifying the process of identifying them. The function TaskAttachment.ReadOne() is vulnerable.
Recommendations Update to version 2.2.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33678
GHSA-JFMM-MJCP-8WQ2
GO-2026-4853
SUSE-SU-2026:1135-1

Affected Products

Vikunja