Improper Access Control in OpenProject Affects Project Management Systems
CVE-2026-52782

9.9CRITICAL

Key Information:

Vendor

Opf

Vendor
CVE Published:
26 June 2026

What is CVE-2026-52782?

OpenProject, a widely used open-source project management software, is affected by an improper access control vulnerability prior to versions 17.3.3 and 17.4.1. This issue arises from an Insecure Direct Object Reference (IDOR) within the project storage settings. A project administrator can manipulate the 'storages_project_storage[project_folder_id]' parameter to gain unauthorized access to another project's Nextcloud or OneDrive folder. This vulnerability allows an attacker to overwrite the Access Control List (ACL) of the target folder, thereby exposing sensitive data to unauthorized users. The vulnerability has been addressed in subsequent releases, ensuring enhanced security for user data.

Affected Version(s)

openproject < 17.3.3 < 17.3.3

openproject >= 17.4.0, < 17.4.1 < 17.4.0, 17.4.1

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.