CVE-2026-27575Disclosure(vikunja / vikunja)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password. An attacker who compromises an account (via brute-force or credential stuffing) can maintain persistent access even after the victim resets their password. Version 2.0.0 contains a fix.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-521CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vikunja

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Disclousre: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-26); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
vikunja

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-25: 1Mentions · 2026-02-26: 3Mentions · 2026-02-27: 2Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 202-2502-2602-27
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Disclousre
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-251
General1
2026-02-263
Disclosure3
2026-02-272
Disclousre1General1
Full discourse6 posts
  • PulsePatch.io@pulsepatchio
    General

    A critical flaw in `Vikunja` (CVE-2026-27575) combines a weak password policy with persistent sessions after password resets. This allows continued unauthorized access. #Vulnerability #InfoSec #GoLang https://www.pulsepatch.io/posts/cve-2026-27575-vikunja-weak-password-persistent-sessions

    Post summary

    The post alerts to a critical flaw in Vikunja involving weak password policy and persistent sessions, but offers no evidence of exploits, patches, or active attacks.

    0000051
    1 followersView on X
  • Aerendir Mobile@AerendirMobile
    Disclousre

    CVE-2026-27575: 1️⃣ Attacker brute-forces weak password 2️⃣ Establishes active session 3️⃣ User discovers breach, changes password 4️⃣ User thinks they're safe 5️⃣ Attacker still has full access via old session CVSS: 9.1 (Critical) Session persistence + weak passwords = game over

    Post summary

    The post describes CVE‑2026‑27575 as a critical vulnerability where weak passwords combined with session persistence allow an attacker to maintain full access even after the victim changes their password. The CVSS score of 9.1 highlights its severity.

    0000088
    7.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27575 Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) with… https://www.cve.org/CVERecord?id=CVE-2026-27575

    Post summary

    The CVE highlights a weak password policy in Vikunja prior to version 2.0.0, allowing easily guessable passwords such as 1234 or password.

    00000111
    56.6K followersView on X
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2026-27575 - CRITICAL Vikunja 🤖 AI Summary: Vikunja task platform allows weak passwords and persistent sessions after password changes, enabling attackers to maintain access via bru... ThreatScore: 91/100 🔗 http://threatmonitor.io/cve/CVE-2026-27575 #cybersecurity #infosec #CVE

    Post summary

    The post announces a critical vulnerability in Vikunja that allows weak passwords and persistent sessions after password changes, enabling attackers to maintain access.

    0000044
    9 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27575: The Zombie Session: Breaking Vikunja's Auth with CVE-2026-27575 CVE-2026-27575 represents a catastrophic failure in the authentication lifecycle of Vikunja, a popular self-hosted task management platform. The vulnerability is a two-hea... https://cvereports.com/reports/CVE-2026-27575

    Post summary

    CVE-2026-27575 is a severe authentication flaw in Vikunja, announced with limited technical detail and no PoC, exploit, or patch information provided.

    0000043
    32 followersView on X
  • CVETodo@CveTodo
    General

    CVE-2026-27575 pertains to Vikunja, an open-source, self-hosted task management platform. Prior to version 2.0.0, Vikunja exhibited two significant security issues: #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-27575

    Post summary

    The post announces CVE‑2026‑27575 affecting Vikunja, labeling it a critical vulnerability with potential remote code execution and privilege escalation, but offers no further technical or mitigation details.

    0000054
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvikunjavikunja---

Explore more