Missing Authorization Vulnerability in Taiga Project Management Software
CVE-2026-65055

6.9MEDIUM

Key Information:

Vendor

Taiga

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65055?

Taiga 6.10.1 suffers from a missing authorization vulnerability that allows attackers to access sensitive information from private projects. By sending unauthenticated GET requests to the filters_data API endpoints using sequential integer project IDs, attackers can enumerate project member details such as user IDs, full names, and gravatar hashes. This vulnerability bypasses the access controls implemented for other API endpoints, highlighting a critical need for enhanced security measures to protect sensitive project data.

Affected Version(s)

taiga-back 6.10.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.