Missing Authorization Vulnerability in OpenProject Project Management Software
CVE-2026-44734
6.5MEDIUM
What is CVE-2026-44734?
OpenProject, an open-source web-based project management software, is affected by a Missing Authorization vulnerability in its CostReportsController. This flaw enables any authenticated user to alter the name, filters, and grouping of public cost reports without the necessary ownership verification or permission checks. An attacker can potentially exploit this vulnerability by discovering the numeric ID of a public report and making unauthorized modifications, compromising the integrity of report data. The issue has been remediated in versions 17.3.2 and 17.4.0.
Affected Version(s)
openproject < 17.3.2
