Junglewise Threat Intelligence

CVE-2026-40103: Vikunja authorization bypass in scoped API tokens

CVE-2026-40103 · Severity: medium · CVSS 5.4 · Published 2026-04-10

Executive brief

Vikunja's scoped API token enforcement for custom project background routes is method-confused, allowing tokens with read-only permissions to perform delete operations.

Affected products

  • go code.vikunja.io/api
  • vikunja vikunja

References

Related threats