OpenProject Vulnerability in Web-Based Project Management Software
CVE-2026-67527

7.6HIGH

Key Information:

Vendor

Opf

Vendor
CVE Published:
30 July 2026

What is CVE-2026-67527?

A vulnerability in OpenProject, an open-source web-based project management software, has been identified that allows authenticated users to exploit certain APIs. Specifically, prior to version 17.6.0, the PATCH /api/v3/work_packages/{id} endpoint permitted users with only edit_work_packages permissions to manipulate file links. This could allow them to detach, hard-delete, or re-parent FileLinks connected to an attacker-controlled work package, revealing sensitive metadata including the origin filename, origin ID, and MIME type. The issue has been addressed in OpenProject version 17.6.0.

Affected Version(s)

openproject < 17.6.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.