<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:30:43 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290879</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290879</link>
      <description>EUVD-2026-290879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290879</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34727</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34727</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanism, the second factor is completely skipped. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanism, the second factor is completely skipped. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34727</guid>
    </item>
    <item>
      <title>GHSA-8jvc-mcx6-r4cg — Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8jvc-mcx6-r4cg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanism, the second factor is completely skipped.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The OIDC callback at `pkg/modules/auth/openid/openid.go:185` issues a JWT directly after user lookup:&lt;/p&gt;
&lt;p&gt;```go
return auth.NewUserAuthTokenResponse(u, c, false)
```&lt;/p&gt;
&lt;p&gt;There are zero references to TOTP in the entire `pkg/modules/auth/openid/` directory. By contrast, the local login handler at `pkg/routes/api/v1/login.go:79-102` correctly implements TOTP verification:&lt;/p&gt;
&lt;p&gt;```go
totpEnabled, err := user2.TOTPEnabledForUser(s, user)
if totpEnabled {
    if u.TOTPPasscode == &amp;#34;&amp;#34; {
        _ = s.Rollback()
        return user2.ErrInvalidTOTPPasscode{}
    }
    _, err = user2.ValidateTOTPPasscode(s, &amp;amp;user2.TOTPPasscode{
        User:     user,
        Passcode: u.TOTPPasscode,
    })
```&lt;/p&gt;
&lt;p&gt;When OIDC `EmailFallback` maps to a local user who has TOTP enabled, the TOTP enrollment is ignored and a full JWT is issued without any second-factor challenge.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2 with Dex as the OIDC provider.&lt;/p&gt;
&lt;p&gt;Setup:
- Vikunja configured with `emailfallback: true` for Dex
- Local user `alice` (id=1) has TOTP enabled&lt;/p&gt;
&lt;p&gt;```python
import requests, re, html
from urllib.parse import parse_qs, urlparse&lt;/p&gt;
&lt;p&gt;TARGET = &amp;#34;http://localhost:3456&amp;#34;
DEX = &amp;#34;http://localhost:5556&amp;#34;
API = f&amp;#34;{TARGET}/api/v1&amp;#34;&lt;/p&gt;
&lt;p&gt;# ver…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanism, the second factor is completely skipped.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The OIDC callback at `pkg/modules/auth/openid/openid.go:185` issues a JWT directly after user lookup:&lt;/p&gt;
&lt;p&gt;```go
return auth.NewUserAuthTokenResponse(u, c, false)
```&lt;/p&gt;
&lt;p&gt;There are zero references to TOTP in the entire `pkg/modules/auth/openid/` directory. By contrast, the local login handler at `pkg/routes/api/v1/login.go:79-102` correctly implements TOTP verification:&lt;/p&gt;
&lt;p&gt;```go
totpEnabled, err := user2.TOTPEnabledForUser(s, user)
if totpEnabled {
    if u.TOTPPasscode == &amp;#34;&amp;#34; {
        _ = s.Rollback()
        return user2.ErrInvalidTOTPPasscode{}
    }
    _, err = user2.ValidateTOTPPasscode(s, &amp;amp;user2.TOTPPasscode{
        User:     user,
        Passcode: u.TOTPPasscode,
    })
```&lt;/p&gt;
&lt;p&gt;When OIDC `EmailFallback` maps to a local user who has TOTP enabled, the TOTP enrollment is ignored and a full JWT is issued without any second-factor challenge.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2 with Dex as the OIDC provider.&lt;/p&gt;
&lt;p&gt;Setup:
- Vikunja configured with `emailfallback: true` for Dex
- Local user `alice` (id=1) has TOTP enabled&lt;/p&gt;
&lt;p&gt;```python
import requests, re, html
from urllib.parse import parse_qs, urlparse&lt;/p&gt;
&lt;p&gt;TARGET = &amp;#34;http://localhost:3456&amp;#34;
DEX = &amp;#34;http://localhost:5556&amp;#34;
API = f&amp;#34;{TARGET}/api/v1&amp;#34;&lt;/p&gt;
&lt;p&gt;# ver…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8jvc-mcx6-r4cg</guid>
    </item>
  </channel>
</rss>
