CVE-2026-28268Disclosure(vikunja / vikunja)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vikunja vikunja systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical logic bug in the token cleanup cron job, reset tokens remain valid forever. This allows an attacker who intercepts a single reset token (via logs, browser history, or phishing) to perform a complete, persistent account takeover at any point in the future, bypassing standard authentication controls. Version 2.1.0 contains a patch for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-459CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vikunja

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-02-28); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
vikunja

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-02-27: 2Mentions · 2026-02-28: 4Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1Mentions · 2026-03-06: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 3Technical Details · 2026-03-02: 1Technical Details · 2026-03-04: 102-2702-2803-0203-0403-06
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
General
111.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure1Patch1
2026-02-284
Disclosure2General1Patch1
2026-03-021
Patch1
2026-03-041
Disclosure1
2026-03-061
Disclosure1
Full discourse9 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28268 Persistent Password Reset Token Vulnerability in Vikunja ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28268 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post merely cites CVE‑2026‑28268 and links to a vulnerability page without offering technical specifics, PoC, exploit, or patch details.

    0001067
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Vikunja, Business Logic Flaw, #CVE-2026-28268 (Critical) https://dailycve.com/vikunja-business-logic-flaw-cve-2026-28268-critical/

    Post summary

    The post announces a newly discovered business logic flaw in Vikunja, identified as CVE‑2026‑28268 and rated critical, without providing details on exploitation or mitigation.

    0000041
    164 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28268 (CVSS:9.8, CRITICAL) is Undergoing Analysis. Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerabil..https://nvd.nist.gov/vuln/detail/CVE-2026-28268 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical business logic vulnerability (CVSS 9.8) in Vikunja versions before 2.1.0 and links to the NVD entry for more details.

    0000050
    173 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Vikunja API alert: CVE-2026-28268 could allow account takeover through reused password reset tokens. Apply the patch and recommended workarounds immediately to protect user accounts. 🔍 Details: https://vulert.com/vuln-db/CVE-2026-28268 #CyberSecurity #VulnerabilityAlert #Vulert https://t.co/JHUZFjbxTX

    Post summary

    The tweet alerts about CVE-2026-28268, warns of account takeover via reused password reset tokens, and urges users to apply the patch and recommended workarounds.

    0000045
    123 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    The `Vikunja` API is susceptible to account takeover (CVE-2026-28268) due to password reset token reuse. Monitor for official patch releases. #Vikunja #Security #AuthBypass https://www.pulsepatch.io/posts/cve-2026-28268-vikunja-account-takeover

    Post summary

    Vikunja API is vulnerable to account takeover via password reset token reuse; users should monitor for official patch releases.

    0000043
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28268 Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of … https://www.cve.org/CVERecord?id=CVE-2026-28268

    Post summary

    The CVE-2026-28268 disclosure identifies a business logic flaw in Vikunja's password reset process affecting versions before 2.1.0.

    00000144
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-28268: Vikunja Password Reset Mechanism Logic Errors Allowing Persistent Account Takeover A critical authentication bypass vulnerability exists in Vikunja, an open-source task management platform, affecting versions prior to 2.1.0. The vulner... https://cvereports.com/reports/CVE-2026-28268

    Post summary

    A critical authentication bypass vulnerability has been disclosed in Vikunja versions prior to 2.1.0, allowing persistent account takeover via logic errors in the password reset mechanism.

    0000044
    32 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28268: CRITICAL] Critical cybersecurity issue in Vikunja task management <2.1.0! Password reset vulnerability allows reuse of tokens, enabling persistent account takeovers. Update to version 2.1.0 ...#cve,CVE-2026-28268,#cybersecurity https://cvefind.com/CVE-2026-28268

    Post summary

    The tweet reports a critical vulnerability in Vikunja that allows token reuse for account takeovers and recommends upgrading to version 2.1.0 to mitigate the issue.

    0000056
    585 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28268 - Critical Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allo... https://www.thehackerwire.com/vulnerability/CVE-2026-28268/ https://t.co/KNVipDelWi

    Post summary

    The text announces a critical business logic vulnerability in Vikunja versions before 2.1.0 that affects the password reset mechanism.

    0000051
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvikunjavikunja---

Explore more