CVE-2026-33315 | go-vikunja up to 2.1.x Caldav Endpoint authentication bypass
A vulnerability was found in go-vikunja vikunja up to 2.1.x. It has been classified as critical. Affected is an unknown function of the component Caldav Endpoint. Performing a manipulation results in authentication bypass using alternate channel.
This vulnerability is identified as CVE-2026-33315. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.