Authorization Bypass in Vikunja Task Management Platform
CVE-2026-57458

8.1HIGH

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-57458?

In Vikunja, an open-source self-hosted task management platform, a vulnerability was identified in version 2.3.0 that allows an attacker to exploit scoped API tokens. Specifically, a token limited to the oauth.authorize permission can make a POST request to /api/v1/oauth/authorize, generating an OAuth authorization code. This code can then be exchanged at /api/v1/oauth/token for a standard bearer JSON Web Token (JWT) and a refresh token, which do not adhere to the original API token's restrictions. This circumvention enables access to routes beyond what was intended for that user. The issue was resolved in version 2.4.0 of Vikunja.

Affected Version(s)

vikunja = 2.3.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.