PT-2026-27454 · Vikunja · Vikunja

Kolaente

·

Published

2026-03-24

·

Updated

2026-03-27

·

CVE-2026-33700

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.2.1
Description Vikunja is a self-hosted task management platform. A flaw exists where the DELETE /api/v1/projects/:project/shares/:share endpoint does not confirm that the link share belongs to the project specified in the URL. An attacker with administrator privileges for any project can delete link shares from other projects by using their own project ID along with the target share ID.
Recommendations Update to version 2.2.1 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-33700
GHSA-F95F-77JX-FCJC
GO-2026-4850
SUSE-SU-2026:1135-1

Affected Products

Vikunja