THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gg93-x632-9ccv (high) — Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key

[GHSA] GHSA-gg93-x632-9ccv (high) — Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key

highgithub_advisoriesPublished 2026-08-28

GHSA-gg93-x632-9ccv Severity: high CVE: CVE-2026-55065

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key

### Summary

A user with only a single self-owned project can permanently destroy the Kanban bucket assignments (`task_buckets`) and task ordering (`task_positions`) of **any other project view in the entire instance**. The `ProjectView.Delete`

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gg93-x632-9ccv