Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and password-reset flooding attacks without throttling restrictions. | |
| Title | Vikunja before 2.6.0 Authentication Bypass via Unthrottled API | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:22.792Z
Reserved: 2026-09-15T11:09:54.873Z
Link: CVE-2026-91972
No data.
Status : Received
Published: 2026-09-15T16:17:54.087
Modified: 2026-09-15T16:17:54.087
Link: CVE-2026-91972
No data.
OpenCVE Enrichment
No data.