Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91983

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.

EPSS

Процентиль: 19%
0.0027
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
github
4 дня назад

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.

EPSS

Процентиль: 19%
0.0027
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863