CVE-2026-35594 - Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVE ID :CVE-2026-35594
Published : April 10, 2026, 3:55 p.m. | 11 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link shar...
Related Vulnerabilities
- CVE-2026-5483: A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` HIGH
- CVE-2026-35597: Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout MEDIUM
- CVE-2026-4482: The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted MEDIUM
- CVE-2026-5774: Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, an MEDIUM
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
Related Coverage
Threat Actors