Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue.
Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover
Problem type
- CWE-287: Improper Authentication
- CWE-290: Authentication Bypass by Spoofing
- CWE-345: Insufficient Verification of Data Authenticity
Affected products
go-vikunja
>= 1.0.0, < 2.4.0 - AFFECTED
References
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xv7q-fvmc-jx96
https://github.com/go-vikunja/vikunja/commit/7854f2729ab72000210b61c25929678fd6901630
https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0
GitHub Security Advisories
GHSA-xv7q-fvmc-jx96
Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover
https://github.com/advisories/GHSA-xv7q-fvmc-jx96Summary
With the per-provider OIDC emailfallback option enabled, Vikunja links an SSO login to a pre-existing local (username+password) account using only the email claim — no email_verified (or Microsoft xms_edov) check and no password check, on the unauthenticated callback. An attacker who can make the configured issuer emit a token bearing a victim's email logs in as that victim with a full session and no victim interaction (the nOAuth / Grafana CVE-2023-3128 class). The 2.3.0 fix for GHSA-8jvc-mcx6-r4cg added a TOTP gate, not an email_verified gate, so users without TOTP remain exposed.
Details
References are pkg/modules/auth/openid/openid.go at HEAD. Identity is first resolved on the immutable (issuer, subject) pair (openid.go:428). On a subject miss with emailfallback on, fallbackSearchUsers adds an email-only lookup against local accounts:
// openid.go:413
searches = append(searches, &user.User{Issuer: user.IssuerLocal, Email: cl.Email})
getUser resolves this via s.Get(), which ANDs non-zero fields -> WHERE issuer='local' AND email=?. Local users always have Issuer="local" (user_create.go:38), so the lookup matches any local account by email alone; getOrCreateUser returns it and the caller mints a session — the password is never read. The claims struct has no email_verified field (openid.go:80) and getClaims never consults one; a repo-wide grep for email_verified/xms_edov returns nothing. The code already warns about this at openid.go:388 ("Discouraged for untrusted providers where someone can set email without verification") — but enforces nothing.
Impact
Unauthenticated takeover of any existing local account (read/write/delete its projects, tasks, attachments, shares), bypassing the password. Scope notes: only issuer='local' accounts are matched (not pure-SSO users); the attacker's sub is not bound to the victim record, but the attack is repeatable; TOTP users are protected by the 2.3.0 enforceTOTPIfRequired gate (openid.go:250), non-TOTP users are not.
Preconditions
- Admin enabled
emailfallback: true(defaults false — a default install is unaffected). - The configured issuer lets the attacker assert the victim's unverified email: a self-service IdP (Keycloak/Authentik/Auth0/Dex with editable email), a mixed federation, or a multi-tenant Entra
/commonapp.iss/audare pinned, but the attacker controlsemail, not the issuer. - The victim has a local account.
Not reachable against a single-tenant IdP that verifies email and disallows self-set addresses.
Recommended Fix
Add email_verified to the claims struct and require it true on the email-fallback branch before linking to a local account; reject when absent/false. For Entra also require xms_edov and pin multi-tenant configs to an allowed-tenant list. Fail closed on an email collision not backed by a verified email from a trusted single-tenant issuer rather than silently logging the caller in.
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xv7q-fvmc-jx96
https://github.com/go-vikunja/vikunja/commit/7854f2729ab72000210b61c25929678fd6901630
https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0
https://github.com/advisories/GHSA-xv7q-fvmc-jx96
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-62367Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-62367",
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"dateUpdated": "2026-10-09T20:49:08.891Z",
"dateReserved": "2026-07-13T22:04:59.677Z",
"datePublished": "2026-10-09T20:49:08.891Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M",
"dateUpdated": "2026-10-09T20:49:08.891Z"
},
"title": "Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover",
"descriptions": [
{
"lang": "en",
"value": "Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO login to a pre-existing local (username+password) account using only the `email` claim from the IdP. The fallback never checks an `email_verified` (or Microsoft `xms_edov`) signal and never requires the matched account's password. An attacker who can obtain a token from the configured issuer carrying a victim's email logs in as that victim with a full session, with no consent or interaction from the victim. Version 2.4.0 fixes the issue."
}
],
"affected": [
{
"vendor": "go-vikunja",
"product": "vikunja",
"versions": [
{
"version": ">= 1.0.0, < 2.4.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-287: Improper Authentication",
"cweId": "CWE-287",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "CWE-290: Authentication Bypass by Spoofing",
"cweId": "CWE-290",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "CWE-345: Insufficient Verification of Data Authenticity",
"cweId": "CWE-345",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xv7q-fvmc-jx96",
"name": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xv7q-fvmc-jx96",
"tags": [
"x_refsource_CONFIRM"
]
},
{
"url": "https://github.com/go-vikunja/vikunja/commit/7854f2729ab72000210b61c25929678fd6901630",
"name": "https://github.com/go-vikunja/vikunja/commit/7854f2729ab72000210b61c25929678fd6901630",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0",
"name": "https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0",
"tags": [
"x_refsource_MISC"
]
}
],
"metrics": [
{}
]
}
}
}