CVE-2026-91984

Summary

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.

Affected Software

VendorProductVersion RangeStatus
go-vikunjavikunja0 < 2.6.0affected
go-vikunjavikunja2.6.0unaffected

Weaknesses

  • CWE-639: Authorization Bypass Through User-Controlled Key

References