No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification. | |
| Title | Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:52:07.941Z
Reserved: 2026-09-15T11:10:41.353Z
Link: CVE-2026-91983
Updated: 2026-09-15T15:52:03.479Z
Status : Received
Published: 2026-09-15T16:17:55.373
Modified: 2026-09-15T16:17:55.373
Link: CVE-2026-91983
No data.
OpenCVE Enrichment
No data.