CVE-2026-91984: Vikunja before 2.6.0 Broken Object-Level Authorization via task-position
Published Sep 15, 2026
·Updated
Vikunja before 2.6.0 fails to validate that user-supplied projectviewid in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.
Affected Software
1 affected component
Vikunja Vikunja<2.6.0
Event History
Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated attacker with access to the task-position POST or PUT endpoints can exploit it. No user interaction is required.
2
What access can an attacker gain through exploitation?
An attacker can insert task position rows into project views belonging to other tenants. The issue affects authorization of the user-supplied project_view_id rather than access to the task itself.
3
Which versions are affected?
Vikunja versions before 2.6.0 are affected. Version 2.6.0 is identified as the version boundary in the available information.