Executive brief
Vikunja's scoped API token enforcement for custom project background routes is method-confused, allowing tokens with read-only permissions to perform delete operations.
Affected products
- go code.vikunja.io/api
- vikunja vikunja
Junglewise Threat Intelligence
CVE-2026-40103 · Severity: medium · CVSS 5.4 · Published 2026-04-10
Vikunja's scoped API token enforcement for custom project background routes is method-confused, allowing tokens with read-only permissions to perform delete operations.