CVE-2026-40103 - Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
CVE ID :CVE-2026-40103
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped AP...
Related Vulnerabilities
- CVE-2026-6000: A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unkn MEDIUM
- CVE-2026-5053: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability al HIGH
- CVE-2026-6005: A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is MEDIUM
- CVE-2026-4664: The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in MEDIUM
- CVE-2026-35621: OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command HIGH
Related Coverage
Threat Actors