CVE-2026-91985: Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
A user who has only read permission on a project can call the single link-share read endpoint and receive the share’s hash field — the secret credential that the anonymous POST /shares/{share}/auth endpoint exchanges for a link-share JWT carrying the share’s permission (read / read-write / admin). A read-only member can therefore mint a write- or admin-level token for the project and perform writes they are not entitled to, while their own user token is correctly refused. This is the remaining variant of the link-share hash disclosure class: GHSA-8hp8-9fhr-pfm9 fixed the list endpoint (ReadAll now requires project admin) but the single-read endpoint’s gate was never aligned. Verified on Vikunja 2.5.0; the weak gate has existed since the endpoint, so earlier versions are likely affected too.
References
- github.com/advisories/GHSA-qfwc-vx6f-3g6g
- github.com/go-vikunja/vikunja/commit/077dc4de79ce6f1ab59215a2c7bf9b30423685f2
- github.com/go-vikunja/vikunja/pull/3688
- github.com/go-vikunja/vikunja/releases/tag/v2.6.0
- github.com/go-vikunja/vikunja/security/advisories/GHSA-qfwc-vx6f-3g6g
- nvd.nist.gov/vuln/detail/CVE-2026-91985
- www.vulncheck.com/advisories/vikunja-before-2.6.0-privilege-escalation-via-link-share-hash
Code Behaviors & Features
Detect and mitigate CVE-2026-91985 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →