CVE-2026-62376

code.vikunja.io/api: Cleartext Storage of Sensitive Information (CVE-2026-62376)

high

Description

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. Version 2.4.0 fixes the issue.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

gocode.vikunja.io/api

Metrics

8.1
Source: cna-v3
Show all metrics
Severity
high
no public PoC known
Published
2026-10-09 21:17 UTC
CWE-312, CWE-916

Weakness classes (CWE)

  • CWE-312Base

    Cleartext Storage of Sensitive Information

    The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

    cwe.mitre.org →
  • CWE-916Base

    Use of Password Hash With Insufficient Computational Effort

    The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-10-09 21:17 UTC· security-advisories@github.com
    • Description: Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. Version 2.4.0 fixes the issue.
    • CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-312
    • CWE: CWE-916