Cross-Tenant Vulnerability in Vikunja Task Management Platform
CVE-2026-55067
5MEDIUM
What is CVE-2026-55067?
Vikunja, a self-hosted task management platform, has a mass assignment vulnerability that affects versions prior to 2.4.0. This flaw allows authenticated users to exploit the Bucket.Update function without proper validation of the selected destination view. As a result, an attacker can relocate their buckets into different tenants' Kanban views, retaining control over malicious content. This could lead to unauthorized access and defacement of other users' data. The issue has been addressed in version 2.4.0.
Affected Version(s)
vikunja < 2.4.0
