Junglewise Threat Intelligence

CVE-2026-35595: Vikunja privilege escalation via project reparenting

CVE-2026-35595 · Severity: high · CVSS 8.3 · Published 2026-04-10

Technologies: code.vikunja.io/api (Go), Vikunja. Vendors: Go, Vikunja.

Executive brief

Vikunja is an open-source task management platform. A vulnerability in how it handles project organization allows a collaborator with basic 'write' access to take full administrative control over a project. By moving a shared project into their own personal folder, an attacker can lock out the original owner, delete the project and its data, or change who has access to it.

Technical details

A privilege escalation vulnerability exists in Vikunja due to insufficient permission checks during project reparenting. The 'CanUpdate' check in 'pkg/models/project_permissions.go' only verifies that a user has 'Write' access to a project when changing its 'parent_project_id'. Because Vikunja uses a recursive Common Table Expression (CTE) to resolve permissions based on the project hierarchy, moving a project under a parent owned by the attacker causes the system to resolve the attacker as the 'Admin' of the moved project. An authenticated attacker with write access can exploit this to gain full administrative control, allowing them to delete projects, manage shares, or remove other users. This is fixed in version 2.3.0.

Affected products

  • Vikunja Vikunja <= 2.2.2

Timeline

  • 2026-04-09: patched: Version 2.3.0 released
  • 2026-04-10: advisory: GitHub Advisory published

References

Related threats