Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xv7q-fvmc-jx96 | Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover |
Fri, 09 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue. | |
| Title | Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover | |
| Weaknesses | CWE-287 CWE-290 CWE-345 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T20:49:08.891Z
Reserved: 2026-07-13T22:04:59.677Z
Link: CVE-2026-62367
No data.
Status : Received
Published: 2026-10-09T21:17:05.470
Modified: 2026-10-09T21:17:05.470
Link: CVE-2026-62367
No data.
OpenCVE Enrichment
No data.
Github GHSA