No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts. | |
| Title | Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:55:04.161Z
Reserved: 2026-09-15T11:09:54.873Z
Link: CVE-2026-91973
Updated: 2026-09-15T15:54:38.336Z
Status : Received
Published: 2026-09-15T16:17:54.230
Modified: 2026-09-15T16:17:54.230
Link: CVE-2026-91973
No data.
OpenCVE Enrichment
No data.