CVE-2026-40103 | go-vikunja up to 2.2.x projects.background_delete password hash instead of password for authentication (GHSA-v479-vf79-mg83)
A vulnerability categorized as problematic has been discovered in go-vikunja vikunja up to 2.2.x. This impacts the function projects.background_delete. Such manipulation leads to use of password hash instead of password for authentication.
This vulnerability is uniquely identified as CVE-2026-40103. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.