Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams. | |
| Title | vikunja before 2.6.0 Team Enumeration via Project Share | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T16:03:30.623Z
Reserved: 2026-09-15T11:10:41.353Z
Link: CVE-2026-91980
Updated: 2026-09-15T16:03:26.911Z
Status : Received
Published: 2026-09-15T16:17:54.940
Modified: 2026-09-15T17:17:43.613
Link: CVE-2026-91980
No data.
OpenCVE Enrichment
No data.