CVE-2026-28268 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-28268 requires immediate attention.

· 3 min read

```html

Executive Summary

A critical business logic vulnerability (CVE-2026-28268) has been identified in the password reset mechanism of vikunja/api. This flaw allows password reset tokens to be reused indefinitely, enabling potential account takeovers. Developers and small teams should act swiftly to mitigate this risk by applying the available patch and following the remediation steps outlined below.

Immediate Action

  • Upgrade to vikunja/api v2.1.0 or later immediately.
  • Review your application logs for any suspicious password reset activities.
  • Temporarily disable password reset functionality until the patch is applied.
  • Implement additional monitoring for account activity to detect unauthorized access.
  • Consult the vendor's advisory for further details and updates: Vendor Advisory.

Affected Versions

  • vikunja/api@<=2.0.9 vulnerable; upgrade to 2.1.0+

Resolution Guide

To resolve this issue, follow the steps below:

git clone https://github.com/go-vikunja/vikunja.git
cd vikunja
git checkout v2.1.0
go build

For package managers, use the following commands:

  • docker pull vikunja/vikunja:v2.1.0 (for Docker users)

Update the vulnerable code snippet in pkg/user/user_password_reset.go as follows:

func ResetPassword(s *xorm.Session, reset *PasswordReset) (userID int64, err error) {
    // ... [Existing Code] ...
    
    // Correct Token Deletion
    err = removeTokens(s, user, TokenPasswordReset) // Correct TokenKind
    if err != nil {
        return
    }
    
    // ... [Remaining Code] ...
}

Detection & Verification

To check if your version is vulnerable, run the following command:

git describe --tags --abbrev=0

Verify the fix by checking for the updated token cleanup logic in pkg/user/token.go:

grep "created < ?" pkg/user/token.go

Risk and Impact

This vulnerability allows an attacker to perform a persistent account takeover by reusing a single valid password reset token. This can result in unauthorized access to user accounts, leading to potential data breaches and loss of sensitive information. The exploit window is effectively infinite, posing a long-term risk if not addressed.

```

Keep reading