Remote Code Execution Vulnerability in OpenProject by OpenProject Foundation
CVE-2026-52780

9.6CRITICAL

Key Information:

Vendor

Opf

Vendor
CVE Published:
26 June 2026

What is CVE-2026-52780?

OpenProject, a popular open-source project management software, is susceptible to a vulnerability that enables cache store poisoning, potentially leading to Remote Code Execution (RCE). Versions prior to 17.3.3 and 17.4.1 are impacted. This flaw allows an attacker to exploit the cache mechanism, possibly executing arbitrary code on the server. Users are strongly advised to upgrade to the latest versions to mitigate this risk. The issue was addressed in versions 17.3.3 and 17.4.1, ensuring enhanced security for OpenProject users.

Affected Version(s)

openproject < 17.3.3 < 17.3.3

openproject >= 17.4.0, < 17.4.1 < 17.4.0, 17.4.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.