CVE-2026-34727 - Vikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path
CVE ID :CVE-2026-34727
Published : April 10, 2026, 3:45 p.m. | 21 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback h...
Related Vulnerabilities
- CVE-2026-32252: Chartbrew is an open-source web application that can connect directly to databases and APIs and use HIGH
- CVE-2026-3690: OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to b HIGH
- CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a MEDIUM
- CVE-2026-35666: OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fa HIGH
- CVE-2026-5479: In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and r HIGH
Related Coverage
Threat Actors