THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-68581 (HIGH 8.1) — Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a targe

[NVD] CVE-2026-68581 (HIGH 8.1) — Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a targe

mednvdPublished 2026-08-02

CVE-2026-68581 CVSS: 8.1 HIGH Published: 2026-08-02T13:16:54.087

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tok

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68581