CVE-2026-33316 is a high-severity vulnerability affecting Vikunja, an open-source task management platform, in versions prior to 2.2.0. This flaw allows previously disabled user accounts to be reactivated by exploiting a weakness in the password reset logic, which incorrectly sets the user status to active without verifying prior disablement. With a CVSS score of 8.1, the vulnerability has a low attack complexity and can be exploited remotely by a disabled user to regain full access to their account, leading to high confidentiality and integrity impacts. There is currently no evidence of active exploitation, nor is public exploit code available. Organizations using affected Vikunja versions should prioritize upgrading to version 2.2.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.0CPE matchmatch criteria | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.