CyberRota Analysis
AI-GeneratedVikunja versions prior to 2.6.0 are vulnerable to an authentication bypass due to insufficient rate limiting on CalDAV BasicAuth endpoints, allowing remote unauthenticated attackers to execute unlimited credential-guessing attempts. This flaw can lead to the compromise of password-only accounts, undermining the security of affected instances. Organizations using Vikunja should prioritize patching to mitigate the risk of unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.