
CVE-2026-68581 Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequenc… https://www.cve.org/CVERecord?id=CVE-2026-68581
Post summary
The CVE discloses a token validation flaw in Vikunja versions 0.22.0 to 2.3.0 that allows improper principal type handling, potentially leading to privilege escalation. No PoC, exploit, or patch information is provided.

