Unauthorized Document Manipulation in OpenProject by OpenProject
CVE-2026-44732

4.3MEDIUM

Key Information:

Vendor

Opf

Vendor
CVE Published:
26 June 2026

What is CVE-2026-44732?

OpenProject, a popular open-source project management tool, has a vulnerability that allows unauthorized users to manipulate project documents. This issue arises from the improper implementation of visibility checks during the document update process. Specifically, an attacker can exploit this flaw by sending crafted PATCH requests that bypass the necessary authorization checks, allowing them to change the project_id of documents they shouldn’t have access to. This issue affects versions of OpenProject before 17.3.2 and 17.4.0 and poses significant risks to project data integrity. Users are encouraged to upgrade to the latest versions to remediate this vulnerability.

Affected Version(s)

openproject < 17.3.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.