THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-44v6-7fxq-vgf4 (medium) — Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0

[GHSA] GHSA-44v6-7fxq-vgf4 (medium) — Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0

medgithub_advisoriesPublished 2026-08-28

GHSA-44v6-7fxq-vgf4 Severity: medium CVE: CVE-2026-55064

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0

## Summary

The fix for CVE-2026-35595 (project re-parenting privilege escalation) only gates reparent operations when `parent_project_id > 0`. A user with Write (but not Admin) permission on a shared ch

Indicators of compromise

Original source: https://github.com/advisories/GHSA-44v6-7fxq-vgf4