Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-47193

OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks_CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historica...

opf openproject < 17.3.3 CVE
MEDIUM 4.3 CVE-2026-55838

RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics_CVE-2026-55838

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metric...

rustfs rustfs <= 1.0.0-beta.7 CVE
HIGH 7.7 CVE-2026-55189

RustFS: FTP frontend skips IAM authorization on object reads_CVE-2026-55189

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read ...

rustfs rustfs >= 1.0.0-alpha.1, <= 1.0.0-beta.8 CVE
HIGH 8.2 CVE-2026-55188

RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials_CVE-2026-55188

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the ...

rustfs rustfs >= 1.0.0-alpha.1, <= 1.0.0-beta.8 CVE
HIGH 8.6 CVE-2026-49991

RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection_CVE-2026-49991

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucke...

rustfs rustfs 1.0.0-beta.4 CVE
MEDIUM 4.3 CVE-2026-49355

OpenProject: Private work package data disclosure through single meeting agenda item API_CVE-2026-49355

OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id`...

opf openproject < 17.4.0 CVE
CRITICAL 9.9 CVE-2026-46386

OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`_CVE-2026-46386

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KE...

opf openproject >= 8.3.0, < 17.2.4 CVE
MEDIUM 6.5 CVE-2026-44736

OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects_CVE-2026-44736

OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated use...

opf openproject < 17.4.0 CVE
MEDIUM 6.5 CVE-2026-44735

OpenProject: Shares API Information Disclosure_CVE-2026-44735

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share detail...

opf openproject < 17.3.2 CVE
MEDIUM 6.5 CVE-2026-44734

OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename_CVE-2026-44734

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in Open...

opf openproject < 17.3.2 CVE