CVE-2026-57458
Received Received - Intake

OAuth Token Privilege Escalation in Vikunja

Vulnerability report for CVE-2026-57458, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at `POST /api/v1/oauth/token` for a normal bearer JSON Web Token (JWT) and refresh token. The resulting credentials are not restricted by the original API token's permissions, allowing access to routes outside its declared scope for the same user. Version 2.4.0 fixes the vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
go-vikunja vikunja = 2.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In Vikunja version 2.3.0, a scoped API token with limited permissions could exploit the OAuth authorization flow to obtain a full-access bearer token. The token was not restricted by the original API token's permissions, allowing unauthorized access to routes beyond its intended scope for the same user.

Impact Analysis

An attacker with a limited API token could escalate privileges and access sensitive user data or perform actions outside their intended permissions. This could lead to data breaches, unauthorized modifications, or complete account compromise for affected users.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to personal or sensitive data, potentially leading to data breaches. Organizations using Vikunja 2.3.0 may face penalties for failing to protect user data under GDPR or HIPAA.

Mitigation Strategies

Upgrade Vikunja to version 2.4.0 or later to fix the vulnerability. Review API tokens with oauth.authorize permissions and revoke any unnecessary tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57458. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart