SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-68582

MEDIUM · CVSS 6.5 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

Vikunja versions 0.24.0 to 2.3.0 are vulnerable due to a broken object-level authorization issue in the task-collection endpoint, allowing unauthorized users with a project share link to access kanban bucket titles and user information from other tenants. This vulnerability can lead to information disclosure, as attackers can exploit the lack of authorization checks to enumerate project views and their existence. Organizations using affected versions should prioritize upgrading to version 2.4.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-68582
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%
Oracle

Original NVD Description

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. For a link-share token holder, the task scope is pinned to the share's own project, but the view is taken from the attacker-controlled path and never re-validated. As a result, a holder of any project share link can read any other tenant's kanban bucket records — bucket titles and the full created_by user object (username, name, id) — for every view in the instance. The same missing pre-authorization view load also creates a project/view-ID existence oracle (404 vs. non-404) usable by link shares and ordinary authenticated users. Task contents remain constrained to the share's own project and are not disclosed. Fixed in 2.4.0.