216.73.216.233

CVE-2026-28268

· Published 27/02/2026 21:16 · Modified 27/02/2026 21:16

Labels: CVE-2026-28268 2026-02-27CVE-2026-28268CWE-459[email protected]

Essential information

Published
27/02/2026 21:16
Modified
27/02/2026 21:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical logic bug in the token cleanup cron job, reset tokens remain valid forever. This allows an attacker who intercepts a single reset token (via logs, browser history, or phishing) to perform a complete, persistent account takeover at any point in the future, bypassing standard authentication controls. Version 2.1.0 contains a patch for the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vikunja / vikunja cpe:2.3:a:vikunja:vikunja:<2.1.0:*:*:*:*:*:*:*

References