Task Management Platform Vulnerability in Vikunja Affects User Permissions
CVE-2026-55064

4.3MEDIUM

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55064?

Vikunja, an open-source self-hosted task management platform, has a vulnerability that allows users with Write permissions on a shared child project to detach it from its parent by exploiting the ability to submit a parent_project_id equal to 0. This vulnerability affects versions 2.3.0 to 2.4.0 and can disrupt the project's permission hierarchy, undermining the intended access controls. The issue was addressed in version 2.4.0, ensuring that the authorization checks are enforced properly.

Affected Version(s)

vikunja >= 2.3.0, < 2.4.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.