CVE-2026-33316Disclosure(vikunja / vikunja)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their accounts. The `ResetPassword()` function sets the user’s status to `StatusActive` after a successful password reset without verifying whether the account was previously disabled. By requesting a reset token through `/api/v1/user/password/token` and completing the reset via `/api/v1/user/password/reset`, a disabled user can reactivate their account and bypass administrator-imposed account disablement. Version 2.2.0 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-862CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vikunja

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
vikunja

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-24: 3Technical Details · 2026-03-24: 203-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33316 - High Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their accounts. Th... https://www.thehackerwire.com/vulnerability/CVE-2026-33316/ https://t.co/CCTWeVFD4d

    Post summary

    The post announces a high‑severity flaw in Vikunja’s password reset logic that lets disabled users regain account access, highlighting the vulnerability but offering no PoC, exploit, patch, or active exploitation details.

    0000059
    145 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33316 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain acces… https://www.cve.org/CVERecord?id=CVE-2026-33316

    Post summary

    The post discloses a CVE (2026-33316) affecting Vikunja, detailing a password‑reset logic flaw that lets disabled users regain access, with the issue fixed in versions 2.2.0 and later.

    0000077
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33316 Authentication Bypass in Vikunja Task Management Platform Before 2.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33316

    Post summary

    The post announces an authentication bypass vulnerability (CVE‑2026‑33316) in Vikunja Task Management Platform, providing only the type of flaw and a link for detail, with no evidence of exploits, patches, or active attacks.

    0000031
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvikunjavikunja---

Explore more