OpenID Connect Authentication Bypass in Vikunja Task Management Platform
CVE-2026-62367
7.5HIGH
What is CVE-2026-62367?
Vikunja, an open-source self-hosted task management platform, has a security issue where enabling the per-provider 'emailfallback' option on OpenID Connect providers allows an attacker to bypass authentication. The vulnerability arises because the platform only verifies the 'email' claim from the identity provider, neglecting to check if the email is verified or requires the local account's password. As a result, an attacker with a valid token containing the victim's email can log in as that user without their consent. This issue affects versions 1.0.0 through 2.3.0 and is fixed in version 2.4.0.
Affected Version(s)
vikunja >= 1.0.0, < 2.4.0
