๐Ÿ” CVE Alert

CVE-2026-76216

HIGH 7.5

Vikunja through 2.4.0 Principal-Type Confusion via LinkSharing

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers with a link-share JWT can remove victims from teams, enumerate and delete victim bot users, or read team rosters by exploiting id collisions in the autoincrement space.

CWE CWE-639
Vendor go-vikunja
Product vikunja
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for go-vikunja vikunja

Be the first to know when new high vulnerabilities affecting go-vikunja vikunja are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

go-vikunja / vikunja
0 โ‰ค 2.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-vikunja/vikunja/security/advisories/GHSA-32r8-5843-4qw2 vulncheck.com: https://www.vulncheck.com/advisories/vikunja-through-principal-type-confusion-via-linksharing

Credits

๐Ÿ” manus-use