MEDIUM 5.3 NVD
CVE-2026-91984
Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can i
Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.
References
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-w39f-h553-h2mx
- https://www.vulncheck.com/advisories/vikunja-before-2.6.0-broken-object-level-authorizatio
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-15 via NVD.
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.