CVE-2026-33676

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related_tasks` field with full task objects for all related tasks without checking whether the requesting user has read permission on those tasks' projects. An authenticated user who can read a task that has cross-project relations will receive full details (title, description, due dates, priority, percent completion, project ID, etc.) of tasks in projects they have no access to. Version 2.2.1 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*

History

27 Mar 2026, 16:12

Type Values Removed Values Added
References () https://github.com/go-vikunja/vikunja/commit/833f2aec006ac0f6643c41872e45dd79220b9174 - () https://github.com/go-vikunja/vikunja/commit/833f2aec006ac0f6643c41872e45dd79220b9174 - Patch
References () https://github.com/go-vikunja/vikunja/pull/2449 - () https://github.com/go-vikunja/vikunja/pull/2449 - Issue Tracking
References () https://github.com/go-vikunja/vikunja/security/advisories/GHSA-8cmm-j6c4-rr8v - () https://github.com/go-vikunja/vikunja/security/advisories/GHSA-8cmm-j6c4-rr8v - Exploit, Vendor Advisory
References () https://vikunja.io/changelog/vikunja-v2.2.2-was-released - () https://vikunja.io/changelog/vikunja-v2.2.2-was-released - Release Notes
First Time Vikunja
Vikunja vikunja
CPE cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*

25 Mar 2026, 15:41

Type Values Removed Values Added
Summary
  • (es) Vikunja es una plataforma de gestión de tareas de código abierto y autoalojada. Antes de la versión 2.2.1, cuando la API de Vikunja devuelve tareas, rellena el campo 'related_tasks' con objetos de tarea completos para todas las tareas relacionadas sin verificar si el usuario solicitante tiene permiso de lectura sobre los proyectos de esas tareas. Un usuario autenticado que puede leer una tarea que tiene relaciones entre proyectos recibirá detalles completos (título, descripción, fechas de vencimiento, prioridad, porcentaje de finalización, ID de proyecto, etc.) de tareas en proyectos a los que no tiene acceso. La versión 2.2.1 corrige el problema.

24 Mar 2026, 20:16

Type Values Removed Values Added
References () https://github.com/go-vikunja/vikunja/security/advisories/GHSA-8cmm-j6c4-rr8v - () https://github.com/go-vikunja/vikunja/security/advisories/GHSA-8cmm-j6c4-rr8v -

24 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 16:16

Updated : 2026-03-27 16:12


NVD link : CVE-2026-33676

Mitre link : CVE-2026-33676

CVE.ORG link : CVE-2026-33676


JSON object : View

Products Affected

vikunja

  • vikunja
CWE
CWE-863

Incorrect Authorization