Security Advisory

CVE-2026-56765

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 13:57:59
Last updated 2026-07-10 17:00:55
Assigner VulnCheck
CVSS score 9.3
State PUBLISHED

Description

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all file attachments across all projects instance-wide.