OVERVIEW: CVE-2026-35596 affects Vikunja, an open-source self-hosted task management platform, in versions prior to 2.3.0. A SQL operator precedence bug in the hasAccessToLabel function allows any authenticated user to enumerate and read labels without proper project access controls, exposing label metadata including titles, descriptions, colors, and creator information. SEVERITY: The vulnerability carries a CVSS score of 4.3 (Medium) with a network attack vector requiring low complexity and authenticated user credentials. The impact is limited to confidentiality with no integrity or availability implications. While the attack requires user authentication, the low barrier to entry and potential for sensitive information disclosure across projects presents moderate risk. EXPLOITATION STATUS: This vulnerability is currently not being actively exploited in the wild, with no public exploit code readily available. The CVE does not appear on the CISA Known Exploited Vulnerabilities list and remains inactive on public tracking lists. Community attention appears limited, though organizations running Vikunja versions prior to 2.3.0 should prioritize updating to remediate this access control weakness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.