OpenID Connect Authentication Bypass in Vikunja Task Management Platform
CVE-2026-62367

7.5HIGH

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-62367?

Vikunja, an open-source self-hosted task management platform, has a security issue where enabling the per-provider 'emailfallback' option on OpenID Connect providers allows an attacker to bypass authentication. The vulnerability arises because the platform only verifies the 'email' claim from the identity provider, neglecting to check if the email is verified or requires the local account's password. As a result, an attacker with a valid token containing the victim's email can log in as that user without their consent. This issue affects versions 1.0.0 through 2.3.0 and is fixed in version 2.4.0.

Affected Version(s)

vikunja >= 1.0.0, < 2.4.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.