Unverified Project Share Deletion in Vikunja Task Management Platform
CVE-2026-33700
6.9MEDIUM
What is CVE-2026-33700?
The Vikunja task management platform, prior to version 2.2.1, suffers from an authorization bypass vulnerability. Specifically, the DELETE API endpoint responsible for removing project shares does not adequately verify the ownership of the share in relation to the specified project. As a consequence, an attacker with administrative privileges to any project can exploit this flaw to maliciously delete link shares from other projects by simply manipulating the project ID in the request. This essential oversight compromises project integrity and confidentiality, emphasizing the importance of updating to version 2.2.1 or above to mitigate this risk.
Affected Version(s)
vikunja < 2.2.1
