CVE-2026-91973: Go-Vikunja Vikunja

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.

Affected products

Published 2026-09-15. Last modified 2026-09-16.