CVE-2026-91973
Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiti
Summary
Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.
Published 2026-09-15 · first seen here 2026-10-10
Hunt & detect
Threat hunt brief, Sigma rule and Splunk / Sentinel / CrowdStrike queries are not available for this item yet.