CVE 4.3 MEDIUM

OpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transfer_CVE-2026-24776

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an agenda item to a different section was not properly checking if the target meeting section is part of the same meeting (or is the backlog, in case of recurring meetings). This allowed an attacker to move a meeting agenda item into a different meeting. The attacker did not get access to meetings, but they could add arbitrary agenda items, that could cause confusions. The vulnerability is fixed in 17.0.2.

Basic Information

ID CVE-2026-24776
Source GitHub_M
Published Feb 6, 2026 at 17:56
Modified Feb 6, 2026 at 18:37

Affected Product

Vendor opf
Product openproject
Version < 17.0.2
Affected Versions opf openproject < 17.0.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.