Broken Object Level Authorization Vulnerability in Vikunja by Vikunja
CVE-2026-68582

9.3CRITICAL

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
2 August 2026

What is CVE-2026-68582?

Vikunja versions between 0.24.0 and 2.3.0 are susceptible to a broken object level authorization (BOLA) flaw within the task-collection endpoint. This vulnerability allows an attacker to access unauthorized project views by manipulating the URL path. Specifically, the endpoint does not verify if the user is authorized before loading the requested project view, creating a security gap for holders of link-share tokens. Consequently, unauthorized users can view kanban bucket records from other tenants, including bucket titles and user details linked to created_by. Additionally, this vulnerability can be exploited to determine the existence of project/view IDs, further undermining the platform's security. The issue is resolved in version 2.4.0.

Affected Version(s)

vikunja 0.24.0 < 2.4.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.