OpenProject Vulnerability in Project Management Software by OPF
CVE-2026-67528

4.3MEDIUM

Key Information:

Vendor

Opf

Vendor
CVE Published:
30 July 2026

What is CVE-2026-67528?

OpenProject, an open-source web-based project management solution, has a vulnerability that allows authenticated non-admin users to exploit GET API calls to enumerate custom option IDs. This occurs due to inadequate visibility checks, permitting access to admin-only user or group custom fields' labels. This vulnerability has been addressed in version 17.6.0, where proper validation measures were implemented to restrict access to sensitive data.

Affected Version(s)

openproject < 17.6.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.