CVE-2026-34727 - Vikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path
CVE ID :CVE-2026-34727
Published : April 10, 2026, 3:45 p.m. | 21 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback h...
Related Vulnerabilities
- CVE-2026-5777: This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bri HIGH
- CVE-2026-39315: Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe() MEDIUM
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
- CVE-2026-40191: ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. N/A
- CVE-2026-35653: OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi HIGH
Related Coverage
Threat Actors