Broken Object Level Authorization Vulnerability in Vikunja by Vikunja
CVE-2026-68582
What is CVE-2026-68582?
Vikunja versions between 0.24.0 and 2.3.0 are susceptible to a broken object level authorization (BOLA) flaw within the task-collection endpoint. This vulnerability allows an attacker to access unauthorized project views by manipulating the URL path. Specifically, the endpoint does not verify if the user is authorized before loading the requested project view, creating a security gap for holders of link-share tokens. Consequently, unauthorized users can view kanban bucket records from other tenants, including bucket titles and user details linked to created_by. Additionally, this vulnerability can be exploited to determine the existence of project/view IDs, further undermining the platform's security. The issue is resolved in version 2.4.0.
Affected Version(s)
vikunja 0.24.0 < 2.4.0
