PT-2026-52916 · Unknown · Openproject

CVE-2026-52785

·

Published

2026-06-26

·

Updated

2026-06-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 17.3.3 OpenProject versions prior to 17.4.1
Description SQL injection exists in the timestamps functionality of the baseline comparison feature. This allows callers to request historic work-package attributes by manipulating the timestamps parameter. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update to version 17.3.3. Update to version 17.4.1.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52785
GHSA-98VW-2R87-FX2R

Affected Products

Openproject