Cross-Tenant Vulnerability in Vikunja Task Management Platform
CVE-2026-55067

5MEDIUM

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55067?

Vikunja, a self-hosted task management platform, has a mass assignment vulnerability that affects versions prior to 2.4.0. This flaw allows authenticated users to exploit the Bucket.Update function without proper validation of the selected destination view. As a result, an attacker can relocate their buckets into different tenants' Kanban views, retaining control over malicious content. This could lead to unauthorized access and defacement of other users' data. The issue has been addressed in version 2.4.0.

Affected Version(s)

vikunja < 2.4.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.