CVE-2026-59097

MEDIUM

Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets

Title source: cna
STIX 2.1

Description

Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can supply an arbitrary project identifier to these endpoints, which bypass permission checks and apply the AllowAny default, to pre-empt project administrators from initializing due dates by creating records before they can do so themselves.

References (5)

Core 5

Scores

CVSS v3 5.3
EPSS 0.0034
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
taiga/taiga-back < 6.10.2
Published Jul 02, 2026
Tracked Since Jul 03, 2026