Task Management Platform Vulnerability in Vikunja Affects User Permissions
CVE-2026-55064
4.3MEDIUM
What is CVE-2026-55064?
Vikunja, an open-source self-hosted task management platform, has a vulnerability that allows users with Write permissions on a shared child project to detach it from its parent by exploiting the ability to submit a parent_project_id equal to 0. This vulnerability affects versions 2.3.0 to 2.4.0 and can disrupt the project's permission hierarchy, undermining the intended access controls. The issue was addressed in version 2.4.0, ensuring that the authorization checks are enforced properly.
Affected Version(s)
vikunja >= 2.3.0, < 2.4.0
