
DailyCVE@dailycve
🟠 Vikunja, API Token Scope Bypass, #CVE-2026-91983 (Medium) -DC-Oct2026-3039 https://dailycve.com/vikunja-api-token-scope-bypass-cve-2026-91983-medium-dc-oct2026-3039/
0000030
239 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🟠 Vikunja, API Token Scope Bypass, #CVE-2026-91983 (Medium) -DC-Oct2026-3039 https://dailycve.com/vikunja-api-token-scope-bypass-cve-2026-91983-medium-dc-oct2026-3039/