CVE-2026-33700 | go-vikunja up to 2.2.0 /api/v1/projects/ authorization (GHSA-f95f-77jx-fcjc)
A vulnerability marked as problematic has been reported in go-vikunja vikunja up to 2.2.0. This affects an unknown function of the file /api/v1/projects/. The manipulation leads to authorization bypass.
This vulnerability is documented as CVE-2026-33700. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.