← Zuruck zu CVEs
CVE-2026-33315
MEDIUM4.3
Beschreibung
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login using Basic Authentication, which in turn allows users to bypass the TOTP on 2FA-enabled accounts. The user can then access standard project information that would normally be protected behind 2FA (if enabled), such as project name, description, etc. Version 2.2.0 patches the issue.
CVE Details
CVSS v3.1 Bewertung4.3
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht3/24/2026
Zuletzt geandert3/24/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
vikunja:vikunja
Schwachen (CWE)
CWE-288
Referenzen
https://github.com/go-vikunja/vikunja/commit/cdf5d30a425d032f749b78b98b828f25ad882615(security-advisories@github.com)
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-47cr-f226-r4pq(security-advisories@github.com)
https://vikunja.io/changelog/vikunja-v2.2.0-was-released(security-advisories@github.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.