PT-2026-52913 · Unknown · Openproject

CVE-2026-52782

·

Published

2026-06-26

·

Updated

2026-06-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 17.3.3 OpenProject versions prior to 17.4.1
Description An Insecure Direct Object Reference (IDOR) exists in the project storage settings. A project administrator can gain unauthorized access to the managed Nextcloud or OneDrive folder of another project by manipulating the storages project storage[project folder id] parameter via a PATCH request to the '/projects//settings/project storages/' endpoint. This allows the attacker to overwrite the Access Control List (ACL)—a set of permissions that defines which users or systems are granted access to objects—on the target folder during the next managed-folder synchronization, effectively hijacking the folder with the attacker project's user list.
Recommendations Update to version 17.3.3. Update to version 17.4.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52782
GHSA-3VPX-94QX-XPW6

Affected Products

Openproject