Unauthorized Document Manipulation in OpenProject by OpenProject
CVE-2026-44732
4.3MEDIUM
What is CVE-2026-44732?
OpenProject, a popular open-source project management tool, has a vulnerability that allows unauthorized users to manipulate project documents. This issue arises from the improper implementation of visibility checks during the document update process. Specifically, an attacker can exploit this flaw by sending crafted PATCH requests that bypass the necessary authorization checks, allowing them to change the project_id of documents they shouldn’t have access to. This issue affects versions of OpenProject before 17.3.2 and 17.4.0 and poses significant risks to project data integrity. Users are encouraged to upgrade to the latest versions to remediate this vulnerability.
Affected Version(s)
openproject < 17.3.2
