Improper Access Control in OpenProject Affects Project Management Systems
CVE-2026-52782
What is CVE-2026-52782?
OpenProject, a widely used open-source project management software, is affected by an improper access control vulnerability prior to versions 17.3.3 and 17.4.1. This issue arises from an Insecure Direct Object Reference (IDOR) within the project storage settings. A project administrator can manipulate the 'storages_project_storage[project_folder_id]' parameter to gain unauthorized access to another project's Nextcloud or OneDrive folder. This vulnerability allows an attacker to overwrite the Access Control List (ACL) of the target folder, thereby exposing sensitive data to unauthorized users. The vulnerability has been addressed in subsequent releases, ensuring enhanced security for user data.
Affected Version(s)
openproject < 17.3.3 < 17.3.3
openproject >= 17.4.0, < 17.4.1 < 17.4.0, 17.4.1
