CVE-2026-34727

Published
View on NVD ↗
CVSS v3
7.4
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanism, the second factor is completely skipped. This vulnerability is fixed in 2.3.0.

The to-do app to organize your life.
GitHubGitHub
4.45K