Get real-time updates on Telegram
P5Verified
CVE-2026-91984: code.vikunja.io/api <= 2.5.0
CVE-2026-91984 affects code.vikunja.io/api. EPSS 0.00264 (percentile 0.16839), scored 2026-10-09. Affected range: <= 2.5.0. Fixed version: 2.6.0.
Affected technology
code.vikunja.io/api · <= 2.5.0
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
Any authenticated user with a single writable task of their own can persist `(task_id, project_view_id, position)` rows into any other tenant's project view (view IDs are small sequential integers and enumerable).
- Product
- code.vikunja.io/api
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00264 · percentile 0.16839 · 2026-10-09
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 22:06:25.045838+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-91984.html