Business Logic Error in OpenProject Web-Based Project Management Software
CVE-2026-44733
5.9MEDIUM
What is CVE-2026-44733?
OpenProject, an open-source web-based project management tool, suffers from a business logic error in its password change functionality. This flaw allows an attacker with an active session to bypass password requirements via a PATCH request to the /api/v3/users/me endpoint. The vulnerability enables unauthorized password changes, posing significant risks to user accounts. This issue has been resolved in versions 17.3.2 and 17.4.0.
Affected Version(s)
openproject < 17.3.2
