DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-PJR3-86V4-5P7W: GHSA-PJR3-86V4-5P7W: Broken Access Control via MAX Aggregation in Vikunja Subtree Permissions

GHSA-PJR3-86V4-5P7W: Broken Access Control via MAX Aggregation in Vikunja Subtree Permissions

Vulnerability ID: GHSA-PJR3-86V4-5P7W
CVSS Score: 5.4
Published: 2026-10-09

Vikunja v2.6.0 contains a permission inheritance regression in pkg/models/project_access.go where explicit down-restrictions on sub-projects are overridden by higher parent project permissions due to MAX aggregation across project tree nodes.

TL;DR

An SQL MAX aggregation flaw in Vikunja v2.6.0 project permission handling causes inherited parent privileges to override explicit child project restrictions, permitting read-only users to perform full administrative operations.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-269 / CWE-284
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low (Authenticated User)
  • CVSS v3.1 Score: 5.4 (Medium)
  • Exploit Status: Proof of Concept Documented
  • CISA KEV Status: Not Listed

Affected Systems

  • Vikunja v2.6.0 (code.vikunja.io/api)
  • Vikunja API: = 2.6.0 (Fixed in: None specified)

Mitigation Strategies

  • Refactor getProjectAccessForUser query logic in pkg/models/project_access.go to enforce nearest-ancestor permission evaluation.
  • Isolate confidential or restricted sub-projects into separate root-level project hierarchies.
  • Avoid assigning high parent permissions when explicit lower sub-project restrictions are required.

Remediation Steps:

  1. Identify projects where sub-project users hold explicit lower rights than parent project rights.
  2. Detach restricted sub-projects from parent project hierarchies in Vikunja v2.6.0 instances.
  3. Apply vendor patches once a patched build restoring nearest-ancestor inheritance is published.

References


Read the full report for GHSA-PJR3-86V4-5P7W on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)