CVE-2026-52782 PUBLISHED

OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources

Assigner: GitHub_M
Reserved: 08.06.2026 Published: 26.06.2026 Updated: 26.06.2026

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor opf
Product openproject
Versions
  • Version < 17.3.3 is affected
  • Version >= 17.4.0, < 17.4.1 is affected

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE