PT-2026-66574 · Unknown · Openproject
CVE-2026-67528
·
Published
2026-07-30
·
Updated
2026-07-31
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenProject versions prior to 17.6.0
Description
Authenticated non-admin users can enumerate sequential custom option IDs to read labels belonging to admin-only user or group custom fields. This occurs because the endpoint "/api/v3/custom options/:id" resolves CustomOption records by global numeric ID and fails to verify the
visible(current user) check for UserCustomField and GroupCustomField options.Recommendations
Update to version 17.6.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openproject