CVE-2026-35595
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires Ca...
Related Vulnerabilities
- CVE-2026-40194: phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_ LOW
- CVE-2026-5724: The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor N/A
- CVE-2025-62718: Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF MEDIUM
- CVE-2026-40212: OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerab MEDIUM
- CVE-2026-34727: Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path HIGH
Related Coverage
Threat Actors