PT-2026-52914 · Unknown · Openproject

CVE-2026-52783

·

Published

2026-06-26

·

Updated

2026-06-29

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 17.3.3 OpenProject versions prior to 17.4.1
Description The Storages module writes the OneDrive/SharePoint userless OAuth access token in plaintext to the Rails.cache using the deterministic key storage.<id>.httpx access token. This token is repopulated by an hourly cron job and every userless-OAuth call site. Since the supported cache backends (file store, memcache, and redis) do not provide encryption at rest, an attacker with read access to the cache backend can recover the Azure-AD application-tier bearer token via an anonymous get request using the memcached binary protocol or the Redis equivalent.
Recommendations Update to version 17.3.3. Update to version 17.4.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52783
GHSA-H83W-5Q5X-PQ27

Affected Products

Openproject