CVE-2026-35594Disclosure(vikunja / vikunja)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization objects entirely from JWT claims without any server-side database validation. When a project owner deletes a link share or downgrades its permissions, all previously issued JWTs continue to grant the original permission level for up to 72 hours (the default service.jwtttl). This vulnerability is fixed in 2.3.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vikunja

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
vikunja

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-10: 204-10
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35594 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing… https://www.cve.org/CVERecord?id=CVE-2026-35594 ----- Traducción: CVE-2026-35594 Vik… http://infoflow.cloud`

    Post summary

    The tweet briefly announces CVE-2026-35594 affecting Vikunja before v2.3.0 and links to the CVE record, but provides no technical, exploit, or patch details.

    0000042
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35594 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing… https://www.cve.org/CVERecord?id=CVE-2026-35594

    Post summary

    CVE-2026-35594 relates to link share authentication in older Vikunja versions, but the text lacks specific technical, exploit, or mitigation details.

    00000613
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvikunjavikunja---

Explore more