CVE-2026-33316 | go-vikunja up to 2.1.x Password Reset token ResetPassword access control
A vulnerability was found in go-vikunja vikunja up to 2.1.x. It has been declared as critical. Affected by this vulnerability is the function ResetPassword of the file /api/v1/user/password/token of the component Password Reset Handler. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2026-33316. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.