


Perceptive Security
SOC/SIEM Consultancy

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric s…
Published:
1 August 2026 at 22:00:00
Alert date:
2 August 2026 at 14:02:49
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Vikunja versions 0.22.0 through 2.3.0 contain a critical authentication bypass vulnerability in API token management. The flaw stems from failure to validate the principal type when resolving identities through the generic web.Auth.GetID() interface. Since user IDs and link-share IDs are independent numeric sequences resolved through the same interface, an attacker can craft a link-share JWT whose numeric ID matches a target user's ID. An authenticated attacker can enumerate a target's user ID via user search, then create link shares until the sequence ID matches the target user's ID, effectively impersonating that user against the /api/v1/tokens endpoints. This allows the attacker to list, create, and delete the victim's API tokens, including issuing new tokens with attacker-chosen scopes under the victim's permissions. The vulnerability is fixed in Vikunja version 2.4.0.
Technical details
Mitigation steps:
Affected products:
Vikunja 0.22.0
Vikunja 2.3.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-68581
https://github.com/go-vikunja/vikunja/commit/95b7e673fb5ee407498fa4b13e8b4c57847a4a0b
https://github.com/go-vikunja/vikunja/commit/e6b25bd57b537ef9a72b5acdadf446ca5ef77bfa
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-vvcv-vpph-h844
https://www.vulncheck.com/advisories/vikunja-through-authentication-bypass-via-principal-id-collision
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
