CVE-2026-35598
MEDIUMVikunja has Missing Authorization on CalDAV Task Read
Title source: cnaDescription
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task's project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on the instance. This vulnerability is fixed in 2.3.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-48ch-p4gq-x46x
X_Refsource_Misc x_refsource_misc
https://github.com/go-vikunja/vikunja/pull/2579
X_Refsource_Misc x_refsource_misc
https://github.com/go-vikunja/vikunja/commit/879462d717351fe5d276ddec5246bdec31b41661
X_Refsource_Misc x_refsource_misc
https://github.com/go-vikunja/vikunja/releases/tag/v2.3.0
Scores
CVSS v3
4.3
EPSS
0.0022
EPSS Percentile
11.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (3)
code.vikunja.io/api
0 - 2.3.0Go
go-vikunja/vikunja
< 2.3.0
vikunja/vikunja
< 2.3.0
Published
Apr 10, 2026
Tracked Since
Apr 10, 2026