<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 18:01:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-273575</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-273575</link>
      <description>EUVD-2026-273575</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-273575</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27575</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27575</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password. An attacker who compromises an account (via brute-force or credential stuffing) can maintain persistent access even after the victim resets their password. Version 2.0.0 contains a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password. An attacker who compromises an account (via brute-force or credential stuffing) can maintain persistent access even after the victim resets their password. Version 2.0.0 contains a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27575</guid>
    </item>
    <item>
      <title>GHSA-3ccg-x393-96v8 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3ccg-x393-96v8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;**Summary**
The application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password.&lt;/p&gt;
&lt;p&gt;An attacker who compromises an account (via brute-force or credential stuffing) can maintain persistent access even after the victim resets their password.&lt;/p&gt;
&lt;p&gt;**Details**&lt;/p&gt;
&lt;p&gt;1. Weak passwords are accepted during registration and password change.
2. No minimum length or strength validation is enforced.
3. After changing the password, previously issued session tokens remain valid.
4. No forced logout occurs across active sessions.&lt;/p&gt;
&lt;p&gt;_Attack scenario:_&lt;/p&gt;
&lt;p&gt;Attacker guesses or obtains weak credentials.
Logs in and obtains active session token.
Victim changes password.
Attacker continues accessing the account using the old session.&lt;/p&gt;
&lt;p&gt;**Steps to Reproduce**&lt;/p&gt;
&lt;p&gt;**1.** Register using a weak password (e.g., 12345678 ).
**2.** Log in and Password Change functionality.
**3.** Change account password with single character (e.g., 1 or a )
**4.** Reuse the old session.
**5.** Observe that access is still granted.&lt;/p&gt;
&lt;p&gt;**Impact**&lt;/p&gt;
&lt;p&gt;- Persistent account takeover
- Unauthorized access to sensitive data
- Increased brute-force success probability
- Elevated risk for administrative accounts&lt;/p&gt;
&lt;p&gt;The combination of weak password controls and improper session invalidation significantly increases both exploitability and impact.&lt;/p&gt;
&lt;p&gt;**Recommendation**
_**Password Policy Improvements:**_&lt;/p&gt;
&lt;p&gt;- Enforce strong pa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;**Summary**
The application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password.&lt;/p&gt;
&lt;p&gt;An attacker who compromises an account (via brute-force or credential stuffing) can maintain persistent access even after the victim resets their password.&lt;/p&gt;
&lt;p&gt;**Details**&lt;/p&gt;
&lt;p&gt;1. Weak passwords are accepted during registration and password change.
2. No minimum length or strength validation is enforced.
3. After changing the password, previously issued session tokens remain valid.
4. No forced logout occurs across active sessions.&lt;/p&gt;
&lt;p&gt;_Attack scenario:_&lt;/p&gt;
&lt;p&gt;Attacker guesses or obtains weak credentials.
Logs in and obtains active session token.
Victim changes password.
Attacker continues accessing the account using the old session.&lt;/p&gt;
&lt;p&gt;**Steps to Reproduce**&lt;/p&gt;
&lt;p&gt;**1.** Register using a weak password (e.g., 12345678 ).
**2.** Log in and Password Change functionality.
**3.** Change account password with single character (e.g., 1 or a )
**4.** Reuse the old session.
**5.** Observe that access is still granted.&lt;/p&gt;
&lt;p&gt;**Impact**&lt;/p&gt;
&lt;p&gt;- Persistent account takeover
- Unauthorized access to sensitive data
- Increased brute-force success probability
- Elevated risk for administrative accounts&lt;/p&gt;
&lt;p&gt;The combination of weak password controls and improper session invalidation significantly increases both exploitability and impact.&lt;/p&gt;
&lt;p&gt;**Recommendation**
_**Password Policy Improvements:**_&lt;/p&gt;
&lt;p&gt;- Enforce strong pa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3ccg-x393-96v8</guid>
    </item>
  </channel>
</rss>
