Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint. | |
| Title | Vikunja before 2.6.0 User Enumeration via v2 API | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:25.523Z
Reserved: 2026-09-15T11:10:41.353Z
Link: CVE-2026-91981
No data.
Status : Received
Published: 2026-09-15T16:17:55.087
Modified: 2026-09-15T16:17:55.087
Link: CVE-2026-91981
No data.
OpenCVE Enrichment
No data.
