Junglewise Threat Intelligence

CVE-2026-59097: Taiga taiga-back missing authorization in due-date API viewsets

CVE-2026-59097 · Severity: medium · CVSS 5.3 · Published 2026-07-02

Executive brief

Taiga, an open-source project management platform, contains a security flaw that allows unauthorized individuals to modify project settings. Specifically, an attacker can remotely create default due-date records for any project without needing a username or password. This can prevent legitimate project administrators from setting up their own due dates and may disrupt project workflows and data integrity.

Technical details

A missing authorization vulnerability exists in the Taiga backend (taiga-back) due to the lack of permission checks in specific API endpoints. The 'create_default' custom actions in the UserStoryDueDateViewSet, TaskDueDateViewSet, and IssueDueDateViewSet fail to call self.check_permissions() before processing a request. Because the framework defaults to an 'AllowAny' permission level when no specific check is invoked, unauthenticated attackers can send POST requests with an arbitrary project_id to inject due-date records. This action can pre-empt project administrators from initializing their own due dates, as the system may return errors if records already exist. The issue is fixed in version 6.10.2 by enforcing IsProjectAdmin checks on these endpoints.

Affected products

  • Taiga taiga-back before 6.10.2

Timeline

  • 2026-05-22: disclosed: Privately reported to vendor via email
  • 2026-07-01: patched: Fix PR submitted to GitHub
  • 2026-07-02: advisory: CVE published and version 6.10.2 released

References