ZeroHour

CVE-2026-91985

moderate

Link-Share Hash Disclosure Enables Privilege Escalation in Vikunja <2.6.0

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Vikunja versions before 2.6.0 improperly expose the link-share hash field in single-share read endpoints, allowing any read-only member of a shared project or team to retrieve the share's secret credential. The attacker can then exchange that hash for a link-share JWT valid at the share's permission level, escalating privileges beyond their read-only role. Depending on the share's configured permissions, this enables unauthorized writes or administrative actions against the affected share. Instances running versions prior to 2.6.0 that use link sharing and grant read-only access to untrusted members are affected. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and no in-the-wild exploitation has been observed.

What to do: Upgrade to Vikunja 2.6.0 or later, which restricts the link-share hash from read endpoints. Because previously disclosed hashes remain valid credentials, rotate or revoke all existing link shares and re-issue them. Review audit logs for unexpected link-share JWT activity and audit which read-only users had access to shares that carried elevated permissions.

Affected
Vikunjabefore 2.6.0
Estimated exposure
moderatelow thousands of internet-exposed self-hosted instances (likely 1k-10k, plus unknown internal deployments) — Vikunja is a self-hosted open-source to-do application popular in homelab and small-team self-hosting communities, and public internet scans typically show only low thousands of exposed instances; the true count including private…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.

Weakness
CWE-200
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.