CVE-2026-91982: Vikunja: TOTP secret is readable after enrollment, no step-up auth
Once a user has TOTP enabled, the API still hands back the raw shared secret to anyone holding that account’s access token. Reading it doesn’t ask for the password, even though disabling TOTP does. So a stolen token, an XSS, or a browser left open is enough to copy the second factor into your own authenticator and keep generating valid codes indefinitely.
References
- github.com/advisories/GHSA-88f6-4rjv-x774
- github.com/go-vikunja/vikunja/pull/3688
- github.com/go-vikunja/vikunja/releases/tag/v2.6.0
- github.com/go-vikunja/vikunja/security/advisories/GHSA-88f6-4rjv-x774
- nvd.nist.gov/vuln/detail/CVE-2026-91982
- www.vulncheck.com/advisories/vikunja-before-2.6.0-totp-secret-disclosure-via-api
Code Behaviors & Features
Detect and mitigate CVE-2026-91982 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →