Authentication Bypass Vulnerability in Vikunja by Go Vikunja
CVE-2026-91973

8.7HIGH

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91973?

Vikunja prior to version 2.6.0 contains a vulnerability that allows unauthenticated remote attackers to bypass authentication controls in CalDAV BasicAuth endpoints. These endpoints lack adequate rate limiting, enabling attackers to execute unlimited credential-guessing requests against specific routes such as /dav, /.well-known, and /feeds. As a result, this vulnerability can potentially lead to compromised password-only accounts due to the ineffective brute-force mitigation mechanisms in place.

Affected Version(s)

vikunja 0 < 2.6.0

vikunja 2.6.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JellowBeanz26
.