Skip to content
payloadreport
Saturday, October 10, 2026Cybersecurity news without the noise70 reports
Vulnerabilities

Vikunja 2.4.0 Fixes Critical IDOR in Task Collection Endpoint

Vikunja has released version 2.4.0 to address a critical flaw that allowed attackers to extract user data via unvalidated view IDs in share links.

Vikunja 2.4.0 Fixes Critical IDOR in Task Collection Endpoint
Illustration: Payload Report

Key points

  • The flaw affects versions 0.24.0 through 2.3.0 of the Vikunja API.
  • CVE-2026-68582 allows extraction of usernames and project view data.
  • The patch restricts view access to authorized projects only.

Vikunja released version 2.4.0 to fix a critical identity flaw in its task management system. The update addresses CVE-2026-68582, which allowed attackers to access unauthorized project data through manipulated share links.

The vulnerability exists in the task-collection endpoint within the Vikunja API. Attackers could extract user details and project structures by exploiting missing authorization checks in the URL path handling.

Technical Context

The root cause lies in the `TaskCollection.ReadAll` function within `pkg/models/task_collection.go`. The code resolved the project view from URL parameters before verifying caller permissions. This allowed unvalidated view IDs to be processed.

For link-share tokens, the system correctly pinned the task scope to the token's project. However, it reused the attacker-supplied view ID without validating it against the share's permissions. This mismatch enabled data leakage.

Who Is Affected

All installations running Vikunja API versions 0.24.0 up to and including 2.3.0 are vulnerable. The flaw exposes bucket titles and full user objects, including usernames and IDs, to anyone holding a valid share link.

The issue also creates an existence oracle for project and view IDs. Attackers can determine if specific IDs exist by observing HTTP 404 responses versus successful requests. This aids further enumeration attacks.

What happens next

Administrators must upgrade to version 2.4.0 to mitigate this risk. The patch adds necessary validation to ensure views match the authorized project for share links. No other fixes have been confirmed by the vendor.

What to do and how to stay safe: Vikunja

  • Check your Vikunja API version immediately to see if it falls within the vulnerable range.
  • Restrict access to Vikunja instances using firewalls or IP allow-lists to reduce exposure.
  • Monitor server logs for unusual activity involving share links or unauthorized view requests.
  • Once the vendor provides an update, deploy it promptly to prevent data leakage.

Step-by-step guide: Vulnerability Scanning for Small Teams: Practical Steps and Limits

General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What specific data can attackers steal via this vulnerability?

Attackers can retrieve bucket titles and full user objects, including usernames, names, and IDs, from any project view on the instance.

Which versions of Vikunja are vulnerable to CVE-2026-68582?

The vulnerability affects all versions from 0.24.0 up to and including 2.3.0 of the Vikunja API package.

Does the patch fix the existence oracle issue?

Yes, the 2.4.0 update addresses the missing pre-authorization checks that allowed attackers to probe for existing project and view IDs.

Sources

  1. GitHub Advisory Database
VikunjaCVE-2026-68582IDORAPI vulnerabilitytask management

Related stories