CSRF Vulnerability Affecting Tuleap Open Source Suite
CVE-2026-24007

4.6MEDIUM

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
2 February 2026

What is CVE-2026-24007?

Tuleap, an Open Source Suite designed for effective management of software development and collaboration, is vulnerable to a Cross-Site Request Forgery (CSRF) attack. The vulnerability arises from inadequate CSRF protection in the Overview inconsistent items feature, allowing attackers to exploit this weakness. By tricking authenticated users into triggering unwanted actions, such as repairing inconsistent items or creating erroneous artifact links from releases, an attacker can significantly disrupt project workflows. This vulnerability has been addressed in specific versions of Tuleap, ensuring users can upgrade to mitigate any potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

tuleap < 17.0.99.1768924735

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.