Critical Flaws in Vikunja Expose Users to Persistent Account Takeovers
ID: 84f0847d-f093-55a1-8dd2-427fb559a530
STIX ID: report--84f0847d-f093-55a1-8dd2-427fb559a530
Feed Name: securityonline.info
Threat Score
Vikunja (all versions up to v2.0.0) contains two highly critical vulnerabilities—CVE-2026-27575 (weak password policies plus failure to terminate existing sessions) and CVE-2026-28268 (a logic error that reverses token cleanup, leaving password-reset tokens effectively permanent)—that together enable persistent account takeover; administrators should upgrade to v2.0.1 and ensure reset tokens are invalidated on use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
