CVE-2026-62367
Received Received - Intake

Vulnerable SSO Email Fallback in Vikunja

Vulnerability report for CVE-2026-62367, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
go-vikunja vikunja >= 1.0.0, < 2.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Vikunja versions 1.0.0 to 2.3.0 have a flaw where enabling the emailfallback option on an OpenID Connect provider links SSO logins to local accounts using only the email claim. The system does not verify if the email is confirmed or require the local account's password, allowing attackers with a token containing a victim's email to gain full access without consent.

Impact Analysis

If you use Vikunja with OpenID Connect and emailfallback enabled, an attacker could impersonate you by exploiting this flaw. They would gain full session access to your account without needing your password or your interaction, potentially accessing sensitive task data.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. It risks data breaches, non-compliance with access controls, and potential legal penalties due to inadequate safeguards.

Mitigation Strategies

Upgrade Vikunja to version 2.4.0 or later to fix the vulnerability. Disable the per-provider emailfallback option if not needed. Review OpenID Connect provider configurations for any enabled emailfallback settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62367. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart