Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. code.vikunja.io/api
  4. ›
  5. CVE-2026-91985

CVE-2026-91985: Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level

October 9, 2026

A user who has only read permission on a project can call the single link-share read endpoint and receive the share’s hash field — the secret credential that the anonymous POST /shares/{share}/auth endpoint exchanges for a link-share JWT carrying the share’s permission (read / read-write / admin). A read-only member can therefore mint a write- or admin-level token for the project and perform writes they are not entitled to, while their own user token is correctly refused. This is the remaining variant of the link-share hash disclosure class: GHSA-8hp8-9fhr-pfm9 fixed the list endpoint (ReadAll now requires project admin) but the single-read endpoint’s gate was never aligned. Verified on Vikunja 2.5.0; the weak gate has existed since the endpoint, so earlier versions are likely affected too.

References

  • github.com/advisories/GHSA-qfwc-vx6f-3g6g
  • github.com/go-vikunja/vikunja/commit/077dc4de79ce6f1ab59215a2c7bf9b30423685f2
  • github.com/go-vikunja/vikunja/pull/3688
  • github.com/go-vikunja/vikunja/releases/tag/v2.6.0
  • github.com/go-vikunja/vikunja/security/advisories/GHSA-qfwc-vx6f-3g6g
  • nvd.nist.gov/vuln/detail/CVE-2026-91985
  • www.vulncheck.com/advisories/vikunja-before-2.6.0-privilege-escalation-via-link-share-hash

Code Behaviors & Features

Detect and mitigate CVE-2026-91985 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.6.0

Fixed versions

  • 2.6.0

Solution

Upgrade to version 2.6.0 or above.

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-639: Authorization Bypass Through User-Controlled Key
  • CWE-862: Missing Authorization

Source file

go/code.vikunja.io/api/CVE-2026-91985.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 11 Oct 2026 00:17:38 +0000.