CVE Explorer
CVE-2026-33668
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths — API tokens, CalDAV basic auth, and OpenID Connect — do not verify user status, allowing disabled or locked users to continue accessing the API and syncing data. Version 2.2.1 patches the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"vikunja","vendor":"go-vikunja","versions":[{"status":"affected","version":">= 0.18.0, < 2.2.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/problemTypes/1/descriptions/0
Source references
6 source assertions{"name":"https://github.com/go-vikunja/vikunja/commit/033922309f492996c928122fb49b691339199c35","tags":["x_refsource_MISC"],"url":"https://github.com/go-vikunja/vikunja/commit/033922309f492996c928122fb49b691339199c35"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/references/1
{"name":"https://github.com/go-vikunja/vikunja/commit/04704e0fde4b027039cf583110cee7afe136fc1b","tags":["x_refsource_MISC"],"url":"https://github.com/go-vikunja/vikunja/commit/04704e0fde4b027039cf583110cee7afe136fc1b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/references/2
{"name":"https://github.com/go-vikunja/vikunja/commit/0b04768d830c80e9fde1b0962db1499cc652da0e","tags":["x_refsource_MISC"],"url":"https://github.com/go-vikunja/vikunja/commit/0b04768d830c80e9fde1b0962db1499cc652da0e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/references/3
{"name":"https://github.com/go-vikunja/vikunja/commit/fd452b9cb6457fd4f9936527a14c359818f1cca7","tags":["x_refsource_MISC"],"url":"https://github.com/go-vikunja/vikunja/commit/fd452b9cb6457fd4f9936527a14c359818f1cca7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/references/4
{"name":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-94xm-jj8x-3cr4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-94xm-jj8x-3cr4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/references/0
{"name":"https://vikunja.io/changelog/vikunja-v2.2.2-was-released","tags":["x_refsource_MISC"],"url":"https://vikunja.io/changelog/vikunja-v2.2.2-was-released"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bfc1a7e34e4c82d10de3d69e3fb2f3c12bbc92c1bb25441e0e2b570e9e0ecfb4 · sha256:dee7c6ed3114e377… · /containers/cna/references/5
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.