PT-2026-52913 · Unknown · Openproject
CVE-2026-52782
·
Published
2026-06-26
·
Updated
2026-06-29
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenProject versions prior to 17.3.3
OpenProject versions prior to 17.4.1
Description
An Insecure Direct Object Reference (IDOR) exists in the project storage settings. A project administrator can gain unauthorized access to the managed Nextcloud or OneDrive folder of another project by manipulating the
storages project storage[project folder id] parameter via a PATCH request to the '/projects//settings/project storages/' endpoint. This allows the attacker to overwrite the Access Control List (ACL)—a set of permissions that defines which users or systems are granted access to objects—on the target folder during the next managed-folder synchronization, effectively hijacking the folder with the attacker project's user list.Recommendations
Update to version 17.3.3.
Update to version 17.4.1.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openproject