Remote Code Execution Vulnerability in ProjectSend Auth Component
CVE-2026-4045
Key Information:
- Vendor
ProjectSend
- Status
- Vendor
- CVE Published:
- 12 March 2026
Badges
What is CVE-2026-4045?
A security vulnerability exists in ProjectSend affecting versions up to r1945, specifically in the Auth.php file. This flaw allows for the manipulation of the ldap_email argument, which can cause discrepancies in the application's responses. An attacker may exploit this issue remotely, although the complexity of the attack is considered high. Security experts have noted that exploiting this vulnerability is difficult, yet the potential risks are significant, as published exploits could be utilized. Despite early notification to the vendor, no response has been received regarding this critical disclosure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
projectsend r1945
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
