logo

Critical Flaws in Vikunja Expose Users to Persistent Account Takeovers

ID: 84f0847d-f093-55a1-8dd2-427fb559a530

STIX ID: report--84f0847d-f093-55a1-8dd2-427fb559a530

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Vikunja (all versions up to v2.0.0) contains two highly critical vulnerabilities—CVE-2026-27575 (weak password policies plus failure to terminate existing sessions) and CVE-2026-28268 (a logic error that reverses token cleanup, leaving password-reset tokens effectively permanent)—that together enable persistent account takeover; administrators should upgrade to v2.0.1 and ensure reset tokens are invalidated on use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.