User Enumeration Vulnerability in Vikunja by Vikunja
CVE-2026-91981
5.3MEDIUM
What is CVE-2026-91981?
In Vikunja versions prior to 2.6.0, an issue has been identified involving improper validation of link-share tokens within the v2 API's user search endpoints. This vulnerability allows attackers who possess a read-only share link to enumerate users associated with projects via the projects endpoint. Furthermore, they can confirm the existence of arbitrary usernames through the global search endpoint, potentially exposing sensitive user information and compromising data privacy.
Affected Version(s)
vikunja 0 < 2.6.0
vikunja 2.6.0
