Authorization Bypass in Vikunja Task Management Platform
CVE-2026-57458
8.1HIGH
What is CVE-2026-57458?
In Vikunja, an open-source self-hosted task management platform, a vulnerability was identified in version 2.3.0 that allows an attacker to exploit scoped API tokens. Specifically, a token limited to the oauth.authorize permission can make a POST request to /api/v1/oauth/authorize, generating an OAuth authorization code. This code can then be exchanged at /api/v1/oauth/token for a standard bearer JSON Web Token (JWT) and a refresh token, which do not adhere to the original API token's restrictions. This circumvention enables access to routes beyond what was intended for that user. The issue was resolved in version 2.4.0 of Vikunja.
Affected Version(s)
vikunja = 2.3.0
