Data Exposure Vulnerability in OpenProject by OpenProject Community
CVE-2026-49355
4.3MEDIUM
What is CVE-2026-49355?
OpenProject, the open-source web-based project management software, is subject to a data exposure vulnerability prior to version 17.4.0. This vulnerability allows unauthorized disclosure of private work package data linked to restricted or inaccessible projects through the API endpoint GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id. Users are strongly encouraged to upgrade to version 17.4.0 or later to mitigate this risk.
Affected Version(s)
openproject < 17.4.0
