THREAT OPS › Threat News › [GHSA] GHSA-f27p-pw2p-9pr4 (medium) — Vikunja has a project duplication bypasses write-permission check on the target parent project
[GHSA] GHSA-f27p-pw2p-9pr4 (medium) — Vikunja has a project duplication bypasses write-permission check on the target parent project
GHSA-f27p-pw2p-9pr4 Severity: medium CVE: CVE-2026-54766
Vikunja has a project duplication bypasses write-permission check on the target parent project
## Summary
The project-duplication endpoint fails to enforce write access to the target parent project. Any authenticated (non-link-share) user can duplicate a project they can read into **any** parent project on the instance, regardless of whet
MITRE ATT&CK techniques
- Content InjectionT1659
Indicators of compromise
- CVE-2026-54766cve
Original source: https://github.com/advisories/GHSA-f27p-pw2p-9pr4