CVE-2026-56765Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all file attachments across all projects instance-wide.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-10: 3Patch / Workaround · 2026-07-10: 3Technical Details · 2026-07-10: 307-10
Signal classification1 categories
Patch
3100.0%
Full discourse3 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-56765 — CVSS 9.8/10 ██████████ Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/3NTj5bwVqj

    Post summary

    The tweet alerts to a critical authorization flaw in Vikunja (CVE-2026-56765) and emphasizes the urgent patch rollout.

    1000076
    65 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Vikunja Instance-Wide Data Breach via Share-Hash Disclosure + Attachment IDOR (CVE-2026-56765) Two chained flaws in Vikunja. The LinkSharing.ReadAll endpoint leaks share hashes to users with only read access, allowing escalation to admin-level shares. Separately, GetTaskAttachment checks permissions against a user-supplied task ID but then fetches the attachment by sequential ID without verifying ownership. By enumerating sequential IDs, an attacker can download and delete every file attachment across all projects, instance-wide - a full data breach with high confidentiality, integrity, and availability impact. 👉Upgrade Vikunja to 2.2.1.

    Post summary

    CVE-2026-56765 in Vikunja allows a data breach through share-hash leakage and attachment IDOR; a patch is available in version 2.2.1.

    00000106
    246 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Vikunja Instance-Wide Data Breach via Share-Hash Disclosure + Attachment IDOR (CVE-2026-56765) Two chained flaws in Vikunja. The LinkSharing.ReadAll endpoint leaks share hashes to users with only read access, allowing escalation to admin-level shares. Separately, GetTaskAttachment checks permissions against a user-supplied task ID but then fetches the attachment by sequential ID without verifying ownership. By enumerating sequential IDs, an attacker can download and delete every file attachment across all projects, instance-wide - a full data breach with high confidentiality, integrity, and availability impact. 👉Upgrade Vikunja to 2.2.1.

    Post summary

    Vikunja suffers a critical data breach via share-hash disclosure and attachment IDOR, allowing attackers to enumerate and delete all attachments; users should upgrade to version 2.2.1.

    00000104
    246 followersView on X

Explore more