Missing Authorization Vulnerability in ProjectSend AJAX Endpoints
CVE-2026-3977

5.3MEDIUM

Key Information:

Vendor
CVE Published:
12 March 2026

What is CVE-2026-3977?

A security issue has been identified in ProjectSend up to version r1945, specifically within the AJAX Endpoints component. This vulnerability arises from a failure to enforce proper authorization controls, allowing attackers to exploit this flaw remotely. To mitigate this risk, deploying the patch with the identifier 35dfd6f08f7d517709c77ee73e57367141107e6b is highly recommended to secure the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

projectsend r1945

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VulDB GitHub Commit Analyzer
.