CVE-2026-33312

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
20/03/2026
Last modified:
24/03/2026

Description

Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, the `DELETE /api/v1/projects/:project/background` endpoint checks `CanRead` permission instead of `CanUpdate`, allowing any user with read-only access to a project to permanently delete its background image. Version 2.2.0 fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* 0.20.2 (including) 2.2.0 (excluding)