Rate Limiting Failure in Vikunja API by Vikunja
CVE-2026-91972
8.7HIGH
What is CVE-2026-91972?
Vikunja versions prior to 2.6.0 expose their /api/v2 public authentication endpoints without proper rate limiting. This lack of controls allows remote unauthenticated attackers to execute unlimited credential guessing, potentially enabling account enumeration and conducting password reset flooding attacks. The failure to impose restrictions on these critical endpoints not only increases the risk of unauthorized access but also disrupts legitimate user activities by overwhelming the server with requests.
Affected Version(s)
vikunja 0 < 2.6.0
vikunja 2.6.0
