CVE-2026-35595 | go-vikunja up to 2.2.x project_permissions.go privileges management (GHSA-2vq4-854f-5c72)
A vulnerability was found in go-vikunja vikunja up to 2.2.x. It has been rated as critical. Impacted is an unknown function of the file pkg/models/project_permissions.go. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-35595. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.