CVE-2026-91985
moderateLink-Share Hash Disclosure Enables Privilege Escalation in Vikunja <2.6.0
Vikunja versions before 2.6.0 improperly expose the link-share hash field in single-share read endpoints, allowing any read-only member of a shared project or team to retrieve the share's secret credential. The attacker can then exchange that hash for a link-share JWT valid at the share's permission level, escalating privileges beyond their read-only role. Depending on the share's configured permissions, this enables unauthorized writes or administrative actions against the affected share. Instances running versions prior to 2.6.0 that use link sharing and grant read-only access to untrusted members are affected. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and no in-the-wild exploitation has been observed.
What to do: Upgrade to Vikunja 2.6.0 or later, which restricts the link-share hash from read endpoints. Because previously disclosed hashes remain valid credentials, rotate or revoke all existing link shares and re-issue them. Review audit logs for unexpected link-share JWT activity and audit which read-only users had access to shares that carried elevated permissions.
| Vikunja | before 2.6.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.
- Weakness
- CWE-200
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.