CyberRota Analysis
AI-GeneratedVikunja versions prior to 2.6.0 are vulnerable due to improper access controls on the link-share hash field, enabling read-only members to access sensitive credentials. This flaw allows attackers to exploit the disclosed hash, obtaining a link-share JWT that grants them elevated permissions for unauthorized writes or administrative actions. Organizations using affected versions of Vikunja should prioritize patching to mitigate the risk of privilege escalation and potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.