PT-2026-66574 · Unknown · Openproject

CVE-2026-67528

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 17.6.0
Description Authenticated non-admin users can enumerate sequential custom option IDs to read labels belonging to admin-only user or group custom fields. This occurs because the endpoint "/api/v3/custom options/:id" resolves CustomOption records by global numeric ID and fails to verify the visible(current user) check for UserCustomField and GroupCustomField options.
Recommendations Update to version 17.6.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67528
GHSA-WR3W-QCHJ-P4CM

Affected Products

Openproject