Missing Authorization Vulnerability in OpenProject Project Management Software
CVE-2026-44734

6.5MEDIUM

Key Information:

Vendor

Opf

Vendor
CVE Published:
26 June 2026

What is CVE-2026-44734?

OpenProject, an open-source web-based project management software, is affected by a Missing Authorization vulnerability in its CostReportsController. This flaw enables any authenticated user to alter the name, filters, and grouping of public cost reports without the necessary ownership verification or permission checks. An attacker can potentially exploit this vulnerability by discovering the numeric ID of a public report and making unauthorized modifications, compromising the integrity of report data. The issue has been remediated in versions 17.3.2 and 17.4.0.

Affected Version(s)

openproject < 17.3.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.