CVE-2026-91973
code.vikunja.io/api: Improper Restriction of Excessive Authentication Attempts (CVE-2026-91973)
Description
Summary
The /dav, /.well-known, and /feeds groups are registered on the root Echo instance with only BasicAuth and no rate limiter. CalDAV BasicAuth accepts the plain account password, so password guessing over /dav is unbounded and never returns 429, while /api/v1/login is throttled from the tenth attempt. The only anti-brute-force control on the instance is therefore bypassable.
Details
pkg/routes/routes.go (~lines 238-249) registers /.well-known, /dav, and /feeds with middleware.BasicAuth(...) and nothing else; registerCalDavRoutes adds no limiter. pkg/routes/caldav/auth.go (~lines 88-93) falls through to user.CheckUserCredentials with the plain account password when no CalDAV token matches. In contrast, /register, /login, etc. are wrapped by unauthRateLimit() — an unconditional 10/min/IP pre-auth floor that ignores ratelimit.enabled (default false).
TOTP-enabled accounts and bot users are correctly refused, so this targets password-only accounts.
PoC (verified at runtime against v2.5.0)
POST /api/v1/login x25 wrong passwords -> 429 from attempt 2 (throttled)
PROPFIND /dav/principals/{user}/ x60 wrong passwords -> 401 x60, 429 x0
GET /feeds/notifications.atom x30 wrong passwords -> 401 x30, 429 x0
PROPFIND /dav/... with correct password -> 207 (proves the 401s are real auth failures)
Impact
The anti-brute-force floor guarding /login is entirely absent on /dav, /feeds, and /.well-known, giving an unbounded credential-guessing surface against account passwords. (bcrypt caps throughput to a few guesses/second, but nothing caps the number of attempts.) Reported as an authentication-control bypass, not a DoS.
Fix
Apply the unconditional pre-auth rate-limit floor to the /dav, /.well-known, and /feeds groups.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-307Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
cwe.mitre.org →
References & sources
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2vendor-advisory
- https://www.vulncheck.com/advisories/vikunja-before-2.6.0-authentication-bypass-via-caldav-basicauththird-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91973advisory
- https://github.com/go-vikunja/vikunja/pull/3688web
- https://github.com/go-vikunja/vikunjapackage
- https://github.com/go-vikunja/vikunja/releases/tag/v2.6.0web
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-09-15 16:17 UTC· disclosure@vulncheck.com
- Description: Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CWE: CWE-307
- CVE Modified2026-09-15 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2
- SSVC: {"id":"CVE-2026-91973","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalI…