Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-68582

Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token
Back to all
CVE

CVE-2026-68582

Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. For a link-share token holder, the task scope is pinned to the share's own project, but the view is taken from the attacker-controlled path and never re-validated. As a result, a holder of any project share link can read any other tenant's kanban bucket records — bucket titles and the full created_by user object (username, name, id) — for every view in the instance. The same missing pre-authorization view load also creates a project/view-ID existence oracle (404 vs. non-404) usable by link shares and ordinary authenticated users. Task contents remain constrained to the share's own project and are not disclosed. Fixed in 2.4.0.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.3
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68582.json, https://github.com/go-vikunja/vikunja/security/advisories/GHSA-rj9j-8772-4h6c, https://nvd.nist.gov/vuln/detail/CVE-2026-68582, https://www.vulncheck.com/advisories/vikunja-broken-object-level-authorization-via-link-share-token

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00266%
EPSS Percentile
0.18442%
Introduced Version
60aeaad5a43a6a1c28d895d132eed7318c9902d1
Fix Available
907850feae3866ae9b16ea1c7b84a4d77273415a

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading