
CVE-2026-34727 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched… https://www.cve.org/CVERecord?id=CVE-2026-34727
Post summary
The CVE concerns an OIDC callback flaw in Vikunja versions prior to 2.3.0 that improperly issues JWT tokens without validating the matched payload. No PoC, exploit code, or active exploitation is referenced.

