SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-91973

HIGH · CVSS 7.5 EPSS 0.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Vikunja versions prior to 2.6.0 are vulnerable to an authentication bypass due to insufficient rate limiting on CalDAV BasicAuth endpoints, allowing remote unauthenticated attackers to execute unlimited credential-guessing attempts. This flaw can lead to the compromise of password-only accounts, undermining the security of affected instances. Organizations using Vikunja should prioritize patching to mitigate the risk of unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91973
Severity
HIGH
CVSS
7.5
EPSS
0.61%

Original NVD Description

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.