CVE 6.9 MEDIUM

OpenProject is vulnerable to user enumeration via the change password function_CVE-2026-22604

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST request to the /account/change_password endpoint with an arbitrary User ID as the password_change_user_id parameter, the resulting error page would show the username for the requested user. Since this endpoint is intended to be called without being authenticated, this allows to enumerate the user names of all accounts registered in an OpenProject instance. This issue has been patched in version 16.6.2.

Basic Information

ID CVE-2026-22604
Source GitHub_M
Published Jan 10, 2026 at 01:07

Affected Product

Vendor opf
Product openproject
Version >= 11.2.1, < 16.6.2
Affected Versions opf openproject >= 11.2.1, < 16.6.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.