
CVE-2026-35595 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrit… https://www.cve.org/CVERecord?id=CVE-2026-35595
Post summary
The post describes CVE‑2026‑35595 by noting that earlier Vikunja releases allowed privilege escalation due to a permissive CanUpdate check; it provides technical context but no PoC, exploit, or patch.

