CVE-2026-35595 - Vulnerability Analysis
HighCVSS: 8.3Last Updated: April 10, 2026
Vikunja - Broken Access Control
Published: April 10, 2026Updated: April 10, 2026Remote Exploitable
Overview
Vikunja < 2.3.0 contains a broken access control vulnerability caused by improper permission checks when changing parent_project_id, letting users escalate permissions to Admin on moved projects, exploit requires user with inherited Write access.
Severity & Score
Severity: High
CVSS Score: 8.3
Impact
Users can escalate their permissions to Admin on projects by changing project parentage, potentially leading to unauthorized project control.
Mitigation
Update to version 2.3.0 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-35595
- Severity
- High
- CVSS Score
- 8.3
- Type
- broken_access_control
- Status
- new
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L