The CVE-2026-68582 record describes a Broken Object Level Authorization (BOLA) vulnerability in Vikunja versions >= 0.24.0 and <= 2.3.0. The task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks) does not verify caller authorization for requested project views. This allows link-share token holders to access kanban bucket records across tenants, including bucket titles and created_by [truncated]
Vikunja versions 0.22.0 through 2.3.0 have an authentication bypass vulnerability due to improper validation of principal types in API token management. An attacker can obtain a target user's numeric ID via authenticated user search, create link shares on an attacker-writable project, and use the resulting link-share JWT to manipulate the target user's API tokens. This CVE record was published on 2026-08- [truncated]