Ad

CVE-2026-33316

HIGH CVSS 3.1: 8.1 EPSS 0.03%
Updated Mar 24, 2026
Vikunja
Parameter Value
CVSS 8.1 (HIGH)
Affected Versions before 2.2.0
Fixed In 2.2.0
Type CWE-284 (Improper Access Control), CWE-863 (Incorrect Authorization), CWE-862 (Missing Authorization)
Vendor Vikunja
Public PoC No

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their accounts. The `ResetPassword()` function sets the user’s status to `StatusActive` after a successful password reset without verifying whether the account was previously disabled.

By requesting a reset token through `/api/v1/user/password/token` and completing the reset via `/api/v1/user/password/reset`, a disabled user can reactivate their account and bypass administrator-imposed account disablement. Version 2.2.0 patches the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Vikunja Vikunja
cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
2.2.0