CVE-2026-35595Disclosure(vikunja / vikunja)

LOWCVSS 8.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new parent project when changing parent_project_id. However, Vikunja's permission model uses a recursive CTE that walks up the project hierarchy to compute permissions. Moving a project under a different parent changes the permission inheritance chain. When a user has inherited Write access (from a parent project share) and reparents the child project under their own project tree, the CTE resolves their ownership of the new parent as Admin (permission level 2) on the moved project. This vulnerability is fixed in 2.3.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vikunja

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
vikunja

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-10: 2Technical Details · 2026-04-10: 204-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35595 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrit… https://www.cve.org/CVERecord?id=CVE-2026-35595

    Post summary

    The post describes CVE‑2026‑35595 by noting that earlier Vikunja releases allowed privilege escalation due to a permissive CanUpdate check; it provides technical context but no PoC, exploit, or patch.

    00010231
    57.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35595 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrit… https://www.cve.org/CVERecord?id=CVE-2026-35595 ----- Traducción: CVE-2026-35595 Vik… http://infoflow.cloud`

    Post summary

    The post discloses a permission‑check flaw in Vikunja that allows users with write access to effectively update, but it offers no PoC, exploit, or remediation details.

    0000038
    67 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvikunjavikunja---

Explore more