CVE-2026-91981: Vikunja: Link-share token can enumerate users through the v2 API
A link-share token, the credential you hand out to let someone view a shared project, can call the v2 user-search endpoints, which it was never meant to reach. The v1 versions of the same endpoints correctly reject link-share tokens; the v2 versions don’t. As a result, anyone with a share link can list every member of the shared project (and its parent projects), and can test whether any username exists anywhere on the instance.
References
- github.com/advisories/GHSA-vfxw-3x8p-2vjr
- github.com/go-vikunja/vikunja/pull/3688
- github.com/go-vikunja/vikunja/releases/tag/v2.6.0
- github.com/go-vikunja/vikunja/security/advisories/GHSA-vfxw-3x8p-2vjr
- nvd.nist.gov/vuln/detail/CVE-2026-91981
- www.vulncheck.com/advisories/vikunja-before-2.6.0-user-enumeration-via-v2-api
Code Behaviors & Features
Detect and mitigate CVE-2026-91981 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →