THREAT OPS › Threat News › [NVD] CVE-2026-68582 (MEDIUM 6.5) — Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the call
[NVD] CVE-2026-68582 (MEDIUM 6.5) — Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the call
CVE-2026-68582 CVSS: 6.5 MEDIUM Published: 2026-08-02T13:16:54.233
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. For a link-share token hold
Indicators of compromise
- CVE-2026-68582cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68582