Vikunja versions before 2.2.1 are affected by a chained vulnerability tracked as CVE-2026-56765 that can expose data across an entire instance. The issue combines an authorization weakness in the LinkSharing.ReadAll endpoint, which discloses share hashes to users with read access, with an insecure direct object reference in GetTaskAttachment, which checks permissions against a user-supplied task ID but retrieves attachments by sequential ID without verifying ownership.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A new vulnerability, CVE-2026-56765, is published describing how the two flaws can be chained to enable unauthenticated instance-wide access to attachments and escalation to admin-level shares. The disclosure classifies the issue as CWE-639 and notes high confidentiality, integrity, and availability impact.
The references state that Vikunja versions before 2.2.1 are affected by a chain involving share hash disclosure in LinkSharing.ReadAll and an attachment IDOR in GetTaskAttachment. Version 2.2.1 is identified as the unaffected release, indicating the issue was fixed by that version.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.