Vikunja, Incorrect Authorization Vulnerability, CVE-2026-33700 (Medium) -DC-Oct2026-3058

Listen to this Post

A project member with Write permission can delete an admin-tier link share on that project due to an authorization bypass flaw. The core issue stems from how the deletion handler binds and evaluates permission checks. Instead of loading the stored link share record from the database to inspect its actual permission tier, the application constructs a temporary object using only the URL-supplied IDs. Because the Go zero value for the permission field evaluates to read-level access, the authorization logic incorrectly falls through to project Write permissions rather than enforcing the required Admin tier, allowing unauthorized deletion of admin-tier link shares by project writers.

DailyCVE Form:

Platform: Vikunja
Version: <= 2.6.0
Vulnerability: Incorrect Authorization
Severity: Medium
date: 2026-09-07

Prediction: 2026-10-15

What Undercode Say

Analysis reveals that the vulnerability exists because the deletion handlers in both API versions bind parameters straight from the incoming route without retrieving the authoritative database model state. Consequently, permission checks evaluate default zero-initialized values rather than the stored link share’s real administrative privilege level.

curl -i -X DELETE "$BASE/api/v2/projects/$PROJECT_ID/shares/$SHARE_ID" \
-H "Authorization: Bearer $WRITER_TOKEN"
curl -i -X DELETE "$BASE/api/v1/projects/$PROJECT_ID/shares/$SHARE_ID" \
-H "Authorization: Bearer $WRITER_TOKEN"

Exploit: (Educational Purposes!)

To exploit this issue, an attacker with a standard Write-level account on a project can target a known sequential link share numeric ID configured with admin privileges. By issuing a direct DELETE request to either the v1 or v2 project share endpoints, the application fails to validate the stored permission tier, incorrectly authorizing the deletion and instantly revoking external access tokens.

Protection: from this CVE

Upgrade to the latest patched version of Vikunja or apply the recommended source patch that forces the application to load the stored link share object from the database prior to evaluating deletion authorization checks. Ensure that deletion requests correctly require Admin-level permissions when the targeted share is configured with administrative privileges.

Impact

An authenticated project collaborator with Write permissions can successfully revoke and invalidate admin-tier access links on projects where they possess write rights. This results in bounded integrity and availability disruption for external consumers relying on those access shares, though it does not permit arbitrary data disclosure, privilege escalation to instance administrator, or cross-project share modifications.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top