Home

Description

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task's project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on the instance. This vulnerability is fixed in 2.3.0.

PUBLISHED Reserved 2026-04-03 | Published 2026-04-10 | Updated 2026-04-14 | Assigner GitHub_M




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-862: Missing Authorization

Product status

< 2.3.0
affected

References

github.com/...ikunja/security/advisories/GHSA-48ch-p4gq-x46x exploit

github.com/...ikunja/security/advisories/GHSA-48ch-p4gq-x46x

github.com/go-vikunja/vikunja/pull/2579

github.com/...ommit/879462d717351fe5d276ddec5246bdec31b41661

github.com/go-vikunja/vikunja/releases/tag/v2.3.0

cve.org (CVE-2026-35598)

nvd.nist.gov (CVE-2026-35598)

Download JSON