CVE-2026-34727 - Vikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path
CVE ID :CVE-2026-34727
Published : April 10, 2026, 3:45 p.m. | 21 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback h...
Related Vulnerabilities
- CVE-2026-34424: Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access to CRITICAL
- CVE-2026-32252: Chartbrew is an open-source web application that can connect directly to databases and APIs and use HIGH
- CVE-2026-35663: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators HIGH
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
- CVE-2026-35660: OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent HIGH
Related Coverage
Threat Actors