CVE-2026-91973: Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth
Summary The /dav, /.well-known, and /feeds groups are registered on the root Echo instance with only BasicAuth and no rate limiter. CalDAV BasicAuth accepts the plain account password, so password guessing over /dav is unbounded and never returns 429, while /api/v1/login is throttled from the tenth attempt. The only anti-brute-force control on the instance is therefore bypassable.
Details pkg/routes/routes.go (~lines 238-249) registers /.well-known, /dav, and /feeds with middleware.BasicAuth(...) and nothing else; registerCalDavRoutes adds no limiter. pkg/routes/caldav/auth.go (~lines 88-93) falls through to user.CheckUserCredentials with the plain account password when no CalDAV token matches. In contrast, /register, /login, etc. are wrapped by unauthRateLimit() — an unconditional 10/min/IP pre-auth floor that ignores ratelimit.enabled (default false).
TOTP-enabled accounts and bot users are correctly refused, so this targets password-only accounts.
PoC (verified at runtime against v2.5.0) POST /api/v1/login x25 wrong passwords -> 429 from attempt 2 (throttled) PROPFIND /dav/principals/{user}/ x60 wrong passwords -> 401 x60, 429 x0 GET /feeds/notifications.atom x30 wrong passwords -> 401 x30, 429 x0 PROPFIND /dav/... with correct password -> 207 (proves the 401s are real auth failures)
Impact The anti-brute-force floor guarding /login is entirely absent on /dav, /feeds, and /.well-known, giving an unbounded credential-guessing surface against account passwords. (bcrypt caps throughput to a few guesses/second, but nothing caps the number of attempts.) Reported as an authentication-control bypass, not a DoS.
Fix Apply the unconditional pre-auth rate-limit floor to the /dav, /.well-known, and /feeds groups.
Other sources
Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/code.vikunja.io/apito a version that resolves this vulnerability.Fixed in 2.6.0 - Upgrade
Upgrade
Vikunjato a version that resolves this vulnerability.Fixed in 2.6.0 - Configuration
Apply the unconditional pre-auth rate-limit floor of 10 requests per minute per IP to the /dav, /.well-known, and /feeds route groups.
Vikunja root Echo instance unauthRateLimit = 10/min/IP
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Vikunja instances running a version before 2.6.0 are affected if their CalDAV BasicAuth endpoints are reachable. The identified routes are /dav, /.well-known, and /feeds.
What does an attacker need to exploit it?
An attacker can exploit the issue remotely without authentication or user interaction. They can make unbounded credential-guessing requests to the affected endpoints.
Which accounts are at risk?
Password-only accounts are at risk of compromise through credential guessing. The vulnerability bypasses the instance's anti-brute-force controls for the affected BasicAuth endpoints.
What should be done if the instance cannot immediately be updated?
The provided information identifies the affected routes but does not specify a vendor-supported workaround. Restricting exposure to /dav, /.well-known, and /feeds may reduce access to the vulnerable endpoints until an update to 2.6.0 or later can be applied.