SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-91985

HIGH · CVSS 7.5 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Vikunja versions prior to 2.6.0 are vulnerable due to improper access controls on the link-share hash field, enabling read-only members to access sensitive credentials. This flaw allows attackers to exploit the disclosed hash, obtaining a link-share JWT that grants them elevated permissions for unauthorized writes or administrative actions. Organizations using affected versions of Vikunja should prioritize patching to mitigate the risk of privilege escalation and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91985
Severity
HIGH
CVSS
7.5
EPSS
0.38%
Exchange

Original NVD Description

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.