CVE-2026-62376
code.vikunja.io/api: Cleartext Storage of Sensitive Information (CVE-2026-62376)
Description
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. Version 2.4.0 fixes the issue.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-312Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
cwe.mitre.org →CWE-916Base
Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
cwe.mitre.org →
References & sources
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-r6w9-259g-gwrvx_refsource_CONFIRM
- https://github.com/go-vikunja/vikunja/commit/00fd2c6155c01faae99be4226b931d8091fd6323x_refsource_MISC
- https://github.com/go-vikunja/vikunja/commit/3a0ea15d8c18ff960bc98ae39950fa7a14b0af7dx_refsource_MISC
- https://github.com/go-vikunja/vikunja/commit/e31ea2de5040fa63bc97cf4df63bafed3bd9ad85x_refsource_MISC
- https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0x_refsource_MISC
- https://github.com/go-vikunja/vikunjapackage
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-10-09 21:17 UTC· security-advisories@github.com
- Description: Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. Version 2.4.0 fixes the issue.
- CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-312
- CWE: CWE-916