Get real-time updates on Telegram
P5Verified
CVE-2026-91980: code.vikunja.io/api <= 2.5.0
CVE-2026-91980 affects code.vikunja.io/api. EPSS 0.00306 (percentile 0.21518), scored 2026-10-09. Affected range: <= 2.5.0. Fixed version: 2.6.0.
Affected technology
code.vikunja.io/api · <= 2.5.0
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project ### Summary When you share a project with a team, the API lets you attach any team on the instance, including teams you have nothing to do with, as long as you're an admin of the project.
- Product
- code.vikunja.io/api
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00306 · percentile 0.21518 · 2026-10-09
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 22:06:25.045838+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-91980.html