LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-35595

CVE-2026-35595 - Vulnerability Analysis

HighCVSS: 8.3

Last Updated: April 10, 2026

Vikunja - Broken Access Control

Published: April 10, 2026Updated: April 10, 2026Remote Exploitable

Overview

Vikunja < 2.3.0 contains a broken access control vulnerability caused by improper permission checks when changing parent_project_id, letting users escalate permissions to Admin on moved projects, exploit requires user with inherited Write access.

Severity & Score

Severity: High
CVSS Score: 8.3

Impact

Users can escalate their permissions to Admin on projects by changing project parentage, potentially leading to unauthorized project control.

Mitigation

Update to version 2.3.0 or later.

Details

CVE ID
CVE-2026-35595
Severity
High
CVSS Score
8.3
Type
broken_access_control
Status
new

CWE

  • CWE-269

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L