A vulnerability categorized as critical has been discovered in go-vikunja vikunja up to 2.3.0. The affected element is the function
web.Auth.GetID of the file /api/v1/tokens of the component API Token Management. Such manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2026-68581. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.