Signal is active with 3 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all file attachments across all projects instance-wide.
🚨Critical - Vikunja Instance-Wide Data Breach via Share-Hash Disclosure + Attachment IDOR (CVE-2026-56765)
Two chained flaws in Vikunja. The LinkSharing.ReadAll endpoint leaks share hashes to users with only read access, allowing escalation to admin-level shares. Separately, GetTaskAttachment checks permissions against a user-supplied task ID but then fetches the attachment by sequential ID without verifying ownership.
By enumerating sequential IDs, an attacker can download and delete every file attachment across all projects, instance-wide - a full data breach with high confidentiality, integrity, and availability impact.
👉Upgrade Vikunja to 2.2.1.
Post summary
CVE-2026-56765 in Vikunja allows a data breach through share-hash leakage and attachment IDOR; a patch is available in version 2.2.1.
🚨Critical - Vikunja Instance-Wide Data Breach via Share-Hash Disclosure + Attachment IDOR (CVE-2026-56765)
Two chained flaws in Vikunja. The LinkSharing.ReadAll endpoint leaks share hashes to users with only read access, allowing escalation to admin-level shares. Separately, GetTaskAttachment checks permissions against a user-supplied task ID but then fetches the attachment by sequential ID without verifying ownership.
By enumerating sequential IDs, an attacker can download and delete every file attachment across all projects, instance-wide - a full data breach with high confidentiality, integrity, and availability impact.
👉Upgrade Vikunja to 2.2.1.
Post summary
Vikunja suffers a critical data breach via share-hash disclosure and attachment IDOR, allowing attackers to enumerate and delete all attachments; users should upgrade to version 2.2.1.