OpenProject Vulnerability in Web-Based Project Management Software
CVE-2026-67527
7.6HIGH
What is CVE-2026-67527?
A vulnerability in OpenProject, an open-source web-based project management software, has been identified that allows authenticated users to exploit certain APIs. Specifically, prior to version 17.6.0, the PATCH /api/v3/work_packages/{id} endpoint permitted users with only edit_work_packages permissions to manipulate file links. This could allow them to detach, hard-delete, or re-parent FileLinks connected to an attacker-controlled work package, revealing sensitive metadata including the origin filename, origin ID, and MIME type. The issue has been addressed in OpenProject version 17.6.0.
Affected Version(s)
openproject < 17.6.0
