OpenProject Vulnerability in Project Management Software by OPF
CVE-2026-67528
4.3MEDIUM
What is CVE-2026-67528?
OpenProject, an open-source web-based project management solution, has a vulnerability that allows authenticated non-admin users to exploit GET API calls to enumerate custom option IDs. This occurs due to inadequate visibility checks, permitting access to admin-only user or group custom fields' labels. This vulnerability has been addressed in version 17.6.0, where proper validation measures were implemented to restrict access to sensitive data.
Affected Version(s)
openproject < 17.6.0
