THREAT OPS › Threat News › [NVD] CVE-2026-68581 (HIGH 8.1) — Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a targe
[NVD] CVE-2026-68581 (HIGH 8.1) — Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a targe
CVE-2026-68581 CVSS: 8.1 HIGH Published: 2026-08-02T13:16:54.087
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tok
Indicators of compromise
- CVE-2026-68581cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68581