CVE-2026-40103
Vikunja ≤ 2.3.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NSummary
CVE-2026-40103 is a medium-severity Use of Password Hash Instead of Password for Authentication (CWE-836) vulnerability in Vikunja Vikunja. Its CVSS base score is 4.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Pass the Hash (T1550.002); ranked at the 13th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to IA-2 (Identification and Authentication (Organizational Users)) and IA-5 (Authenticator Management) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-21494
Vulnerability Data
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement for custom project background routes is method-confused. A token with only projects.background can successfully delete a project background, while a token with only projects.background_delete…
more
is rejected. This is a scoped-token authorization bypass. This vulnerability is fixed in 2.3.0.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Requires proper identification and authentication of users, which structurally precludes accepting password hashes in place of passwords.
Authenticator management requires secure distribution, verification, and handling of passwords rather than allowing direct submission and comparison of hashes.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Proper authentication mechanisms require passwords (not pre-hashed values) to be supplied by the claimant and verified server-side.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Directly requires secure handling and protection of authentication credentials, preventing storage or comparison of password hashes as if they were passwords.
Mandates secure authentication mechanisms that preclude the flawed practice of treating password hashes as authenticators.
Requires proper cryptographic practices for protecting passwords, indirectly mitigating misuse of hashes in authentication.
Secure coding guidance can prevent this implementation error but does not address the control's broader intent.