CVE-2026-35594 - Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVE ID :CVE-2026-35594
Published : April 10, 2026, 3:55 p.m. | 11 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link shar...
Related Vulnerabilities
- CVE-2026-5053: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability al HIGH
- CVE-2026-33698: Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise N/A
- CVE-2026-40103: Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds MEDIUM
- CVE-2026-35597: Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout MEDIUM
- CVE-2026-35601: Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output MEDIUM
Related Coverage
Threat Actors