๐Ÿ” CVE Alert

CVE-2026-91980

MEDIUM 4.3

vikunja before 2.6.0 Team Enumeration via Project Share

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams.

CWE CWE-200
Vendor go-vikunja
Product vikunja
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for go-vikunja vikunja

Be the first to know when new medium vulnerabilities affecting go-vikunja vikunja are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

go-vikunja / vikunja
0 < 2.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-vikunja/vikunja/security/advisories/GHSA-39p5-2wrr-xh29 vulncheck.com: https://www.vulncheck.com/advisories/vikunja-before-2.6.0-team-enumeration-via-project-share

Credits

๐Ÿ” 0xcelien