Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91981

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint.

EPSS

Процентиль: 15%
0.00241
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
github
3 дня назад

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint.

EPSS

Процентиль: 15%
0.00241
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200