Arbitrary Project Duplication Vulnerability in Vikunja Task Management Platform
CVE-2026-54766

5.3MEDIUM

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-54766?

Vikunja is an open-source self-hosted task management platform that contains a vulnerability allowing an authenticated user to duplicate any project beneath a target parent project without proper permission checks. This flaw exists because the duplication process bypasses necessary write-permission verifications, resulting in possible unauthorized content injection into another user's project hierarchy. The issue has been addressed in version 2.4.0, highlighting the importance of updating to safeguard against such vulnerabilities.

Affected Version(s)

vikunja >= 0.21.0, < 2.4.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.