CVE-2026-62367
code.vikunja.io/api: Improper Authentication (CVE-2026-62367)
Description
Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1.0.0Metrics
Show all metrics
Weakness classes (CWE)
CWE-287Class
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
cwe.mitre.org →CWE-290Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
cwe.mitre.org →CWE-345Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
cwe.mitre.org →
References & sources
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xv7q-fvmc-jx96x_refsource_CONFIRM
- https://github.com/go-vikunja/vikunja/commit/7854f2729ab72000210b61c25929678fd6901630x_refsource_MISC
- https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0x_refsource_MISC
- https://github.com/go-vikunja/vikunjapackage
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-10-09 21:17 UTC· security-advisories@github.com
- Description: Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue.
- CVSS V4.0: AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE: CWE-287
- CWE: CWE-345