---
id: CVE-2026-91980
title: >-
  vikunja before 2.6.0 fails to validate team access when attaching teams to
  projects, allowing authenticated users to enumerate all teams and members
summary: >-
  vikunja before 2.6.0 fails to validate team access when attaching teams to
  projects, allowing authenticated users to enumerate all teams and members.
  Attackers can attach arbitrary team IDs via the project teams endpoint to
  retrieve comp…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: go-vikunja
product: vikunja
affected:
  - vikunja < 2.6.0
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:49:18.987'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91980'
references:
  - url: >-
      https://github.com/go-vikunja/vikunja/security/advisories/GHSA-39p5-2wrr-xh29
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vikunja-before-2.6.0-team-enumeration-via-project-share
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/go-vikunja/vikunja/security/advisories/GHSA-39p5-2wrr-xh29
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T16:03:13.766818Z'
ingestedAt: '2026-09-15T15:39:12.912Z'
epss: 0.00306
epssPercentile: 0.20876
---

## Overview

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
