Listen to this Post
The vulnerability exists in Vikunja version 2.6.0 where server-side session revocation semantics fail to cover the WebSocket boundary entirely.
When users attempt to revoke a specific session using the DELETE /api/v2/user/sessions/{id} endpoint, or trigger account-wide invalidations via TOTP enrollment, the system successfully terminates REST sessions and invalidates refresh tokens.
However, the WebSocket endpoint located at GET /api/v2/ws handles client authentication exclusively through the first client message.
The internal function Connection.handleAuth validates the incoming JSON Web Token using auth.GetUserIDFromToken, which checks cryptographic signatures and token types.
Crucially, it never resolves the sid or session ID claim against the active sessions table in the database.
Because no session lookup or continuous re-validation occurs along the WebSocket pathway, any pre-established connection remains fully active in the hub.
Furthermore, brand-new WebSocket connections can be successfully established using access tokens whose underlying server sessions have already been explicitly deleted.
This architectural oversight means that stolen or leaked access tokens convert directly into persistent data channels.
These channels survive all user-initiated revocation actions, continuing to push live notifications containing sensitive comment mentions, task metadata, and project content indefinitely.
Attackers holding a pre-revocation token can maintain silent, unmonitored access until they manually disconnect, bypassing security controls completely.
DailyCVE Form:
Platform: Self-Hosted Vikunja
Version: Version 2.6.0
Vulnerability: Session Revocation Bypass
Severity: Critical Level
date: August 27, 2026
Prediction: Already Patched Now
What Undercode Say:
Analytics and behavioural review of the WebSocket authentication handler show a fundamental disconnect between REST state management and persistent connection pools. The absence of sid verification during connection initialization allows tokens to outlive their server-side validity.
Bash commands and codes related to the blog
Deploy local Vikunja instance for testing ./deployment/deploy.sh Run the proof of concept exploit script cd poc && ./poc.sh
import jwt Example token check snippet ignoring session lookup token = jwt.decode(tokenString, secret, algorithms=["HS256"]) userId = claims["user_id"] Missing: db.CheckSessionExists(claims["sid"])
Exploit: (Educational Purposes!)
To demonstrate the flaw, an attacker authenticates a WebSocket connection using a valid user JWT before the victim revokes all sessions. After the victim calls DELETE /api/v2/user/sessions/{id} and the session list reports zero active entries, the established WebSocket channel continues receiving real-time notification pushes. An attacker can also initiate a brand-new connection using the same deleted-session token, successfully bypassing the revocation check and receiving full payload data including tasks and project comments.
Protection: from this CVE
To remediate this vulnerability, maintainers must update the WebSocket authentication handler (handleAuth) to explicitly resolve the sid claim against the active sessions table during the initial handshake. Additionally, the application should implement real-time event listeners or heartbeat checks to drop active hub connections immediately when their corresponding server session is revoked, deleted, or invalidated via TOTP enrollment. Users should upgrade to the latest patched release of Vikunja immediately.
Impact:
The impact of CVE-2026-78465 is severe because session revocation is the primary defense mechanism relied upon by users when a device is lost or token theft is suspected. Since the WebSocket channel silently excludes revocation checks, leaked access tokens can be leveraged to establish persistent, unbounded push channels. Attackers retain continuous access to sensitive notifications, comment mentions, and project metadata across all revocation attempts until manual disconnection occurs, leading to prolonged unauthorized data exposure.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

