Privilege Escalation Vulnerability in OpenProject Web-Based Project Management Software
CVE-2026-40896

6.5MEDIUM

Key Information:

Vendor

Opf

Vendor
CVE Published:
20 April 2026

What is CVE-2026-40896?

OpenProject, the open-source web-based project management software, contains a vulnerability that allows users with manage_agendas permissions to inject agenda items into meetings across various projects. This exploitation is possible even in projects where the user has no permissions or knowledge of the target content. The attacker can manipulate the system by sequentially iterating through section IDs, resulting in unauthorized additions to any project's meeting agenda. The issue is resolved in version 17.3.0, emphasizing the importance of timely updates for affected installations.

Affected Version(s)

openproject < 17.3.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.