CVE-2026-91983 PUBLISHED

Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter

Assigner: VulnCheck
Reserved: 15.09.2026 Published: 15.09.2026 Updated: 15.09.2026

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor go-vikunja
Product vikunja
Versions Default: unaffected
  • affected from 1.0.0 to 2.6.0 (excl.)
  • Version 2.6.0 is unaffected

References

Problem Types

  • Incorrect Authorization CWE