CVE-2026-91985: Vikunja before 2.6.0 Privilege Escalation via Link Share Hash

Published Sep 15, 2026
·
Updated

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.

Affected Software

1 affected component
Vikunja Vikunja<2.6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Vikunja to a version that resolves this vulnerability.

    Fixed in 2.6.0
  2. Configuration

    Update Vikunja so single-share read endpoints properly restrict access to the link-share hash field, preventing read-only members from obtaining the share's secret credential.

    Vikunja link-share single-share read endpoints Access control for link-share hash field = restricted (read-only members must not be able to obtain the share's secret credential)

Event History

Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Vikunja instances before 2.6.0 are affected where a read-only member can access a single-share read endpoint that exposes a link-share hash. The disclosed hash can be exchanged for a JWT carrying the link share's permission level.

2

What access does an attacker need to exploit it?

An attacker needs read-only membership and access to the affected single-share read endpoint. No separate administrative privileges are required before obtaining the hash.

3

What can an attacker do after obtaining the link-share hash?

They can exchange the hash for a link-share JWT and operate at the permission level assigned to that share. This can enable unauthorized writes or administrative actions when the share grants those permissions.

4

How can I tell whether my deployment is affected?

Deployments running Vikunja before 2.6.0 should be considered affected. Review whether read-only members can retrieve link-share hashes through single-share read endpoints.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203