CVE-2026-33312 | vikunja up to 2.1.x background authorization (GHSA-564f-wx8x-878h / EUVD-2026-13708)
A vulnerability, which was classified as problematic, was found in vikunja up to 2.1.x. Affected by this vulnerability is an unknown functionality of the file /api/v1/projects/:project/background. Such manipulation leads to incorrect authorization.
This vulnerability is listed as CVE-2026-33312. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.