CVE-2026-35594 - Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVE ID :CVE-2026-35594
Published : April 10, 2026, 3:55 p.m. | 11 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link shar...
Related Vulnerabilities
- CVE-2026-35660: OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent HIGH
- CVE-2026-35600: Vikunja has HTML Injection via Task Titles in Overdue Email Notifications MEDIUM
- CVE-2026-35601: Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output MEDIUM
- CVE-2026-35598: Vikunja Missing Authorization on CalDAV Task Read MEDIUM
- CVE-2026-35651: OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerabilit MEDIUM
Related Coverage
Threat Actors