Unverified Project Share Deletion in Vikunja Task Management Platform
CVE-2026-33700

6.9MEDIUM

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
24 March 2026

What is CVE-2026-33700?

The Vikunja task management platform, prior to version 2.2.1, suffers from an authorization bypass vulnerability. Specifically, the DELETE API endpoint responsible for removing project shares does not adequately verify the ownership of the share in relation to the specified project. As a consequence, an attacker with administrative privileges to any project can exploit this flaw to maliciously delete link shares from other projects by simply manipulating the project ID in the request. This essential oversight compromises project integrity and confidentiality, emphasizing the importance of updating to version 2.2.1 or above to mitigate this risk.

Affected Version(s)

vikunja < 2.2.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.