LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-33473

vikunja · vikunja

Published
CVSS5.7
Severitymedium
WeaknessCWE-287
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Description

Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.2.1 patches the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33473

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33473.