Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-56765: Vikunja before 2.2.1 exposes sensitive share links and attachments

CVE-2026-56765 CVE-2026-56765
Summary

Vikunja, a task management software, has a security flaw that lets unauthorized users access sensitive share links and attachments. This could lead to unauthorized access to confidential files and data. To fix this, update to version 2.2.1 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
vikunja vikunja < 2.2.1
Original title
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The ...
Original description
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all file attachments across all projects instance-wide.
nvd CVSS3.1 9.8
nvd CVSS4.0 9.3
Vulnerability type
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 10 Jul 2026