CVE-2026-57458 - Vikunja: Scoped API token can mint unrestricted OAuth session credentials
CVE ID :CVE-2026-57458 Published : Oct. 9, 2026, 8:46 p.m. | 43 minutes ago Description :Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth...