User Enumeration Vulnerability in OpenProject by OpenProject Management
CVE-2026-44731

4.3MEDIUM

Key Information:

Vendor

Opf

Vendor
CVE Published:
26 June 2026

What is CVE-2026-44731?

OpenProject, a widely used open-source project management tool, has a security vulnerability that allows malicious actors to confirm the existence of user accounts. This issue arises from the application’s meetings filter feature, where an attacker can input various user IDs and analyze the different responses from the server. When a valid user ID is queried, the server reveals this information by disclosing the user’s full name. This behavior enables an attacker to enumerate valid accounts by testing multiple user IDs. The issue was addressed in versions 17.3.2 and 17.4.0, highlighting the importance of keeping software updated to mitigate such security risks.

Affected Version(s)

openproject < 17.3.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.