Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-56765: Vikunja before 2.2.1 exposes sensitive share links and attachments
CVE-2026-56765
CVE-2026-56765
Summary
Vikunja, a task management software, has a security flaw that lets unauthorized users access sensitive share links and attachments. This could lead to unauthorized access to confidential files and data. To fix this, update to version 2.2.1 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vikunja | vikunja | < 2.2.1 |
Original title
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The ...
Original description
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all file attachments across all projects instance-wide.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-639
Authorization Bypass Through User-Controlled Key
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 10 Jul 2026