LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-33700

vikunja · vikunja

Published
CVSS4.9
Severitymedium
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Description

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:project/shares/:share` endpoint does not verify that the link share belongs to the project specified in the URL. An attacker with admin access to any project can delete link shares from other projects by providing their own project ID combined with the target share ID. Version 2.2.1 patches the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33700

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33700.