CVE 4.3 MEDIUM

OpenProject is Vulnerable to Insecure Direct Object Reference in Meetings_CVE-2026-22605

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3.

Basic Information

ID CVE-2026-22605
Source GitHub_M
Published Jan 10, 2026 at 01:07

Affected Product

Vendor opf
Product openproject
Version < 16.6.3
Affected Versions opf openproject < 16.6.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.