CVE-2026-62376
Received Received - Intake

Plaintext Token Storage in Vikunja Allows Account Takeover

Vulnerability report for CVE-2026-62376, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. Version 2.4.0 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
go-vikunja vikunja < 2.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-916 The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Vikunja versions before 2.4.0 store sensitive tokens like password-reset, email-confirmation, and account-deletion tokens in plaintext in the database. An attacker with database access could use these tokens to take over user accounts without needing passwords.

Detection Guidance

This vulnerability involves plaintext storage of sensitive tokens in the Vikunja database. To detect it, check the user_tokens table in your Vikunja database for any unexpired password-reset, email-confirmation, or account-deletion tokens. Look for plaintext values in the token column. If tokens are stored in plaintext, upgrade to Vikunja version 2.4.0 or later immediately.

Impact Analysis

If you use a vulnerable Vikunja version, an attacker could gain full control of your account by exploiting exposed tokens. This could lead to unauthorized access to your tasks, data, or other sensitive information stored in the application.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR and HIPAA by exposing personal data through plaintext token storage. It may lead to unauthorized access, data breaches, and non-compliance with privacy regulations.

Mitigation Strategies

Upgrade Vikunja to version 2.4.0 or later to fix the plaintext token storage issue. Review database backups and storage configurations to ensure tokens are not exposed. Rotate all pending password-reset, email-confirmation, and account-deletion tokens immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62376. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart