CVE-2026-76216

Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers with a link-share JWT can remove victims from teams, enumerate and delete victim bot users, or read team rosters by exploiting id collisions in the autoincrement space.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 14:17

Updated : 2026-09-16 20:18


NVD link : CVE-2026-76216

Mitre link : CVE-2026-76216

CVE.ORG link : CVE-2026-76216


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key