Skip to content
Vikunja Authentication Bypass Vulnerabilities Discovered

Vikunja Authentication Bypass Vulnerabilities Discovered

First seen 16 Sep 2026, 06:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 07:22 UTC
  • Two authentication bypass vulnerabilities in Vikunja before version 2.6.0.
  • Exploitation methods include Caldav Basic Authentication and unthrottled API access.
  • Immediate action is recommended as vulnerabilities are currently unpatched.

Two critical authentication bypass vulnerabilities have been identified in Vikunja versions prior to 2.6.0. The first vulnerability allows unauthorized access via Caldav Basic Authentication, while the second exploits an unthrottled API. These vulnerabilities could potentially allow attackers to gain unauthorized access to sensitive data. Organizations using affected versions are at risk, particularly those relying on Caldav for calendar management and API integrations. No specific CVEs have been assigned yet, but immediate action is advised for users to mitigate risks. Both vulnerabilities were disclosed on September 16, 2026, and are currently unpatched. Security teams are urged to monitor for further updates and apply patches as soon as they are available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
Vulnerability disclosure
Two authentication bypass vulnerabilities in Vikunja versions before 2.6.0 were disclosed, affecting users relying on Caldav and API integrations.
VulnCheck
2026-09-16
Advisory published
VulnCheck published advisories for both vulnerabilities, urging immediate attention from affected organizations.
VulnCheck

More articles in this cluster (2)