Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-52782: OpenProject: Unauthorized Project Access via Project Settings
CVE-2026-52782
Summary
A project administrator in one project can access and manage the files of another project on the same storage. This is a security risk because it allows unauthorized access to sensitive project information. To fix this, update to OpenProject version 17.3.3 or 17.4.1 or later.
Original title
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storag...
Original description
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources. A project-admin in one project can hijack the managed Nextcloud or OneDrive folder of another project on the same storage by writing the victim project's project_folder_id into the attacker's Storages::ProjectStorage row. The next managed-folder sync overwrites the ACL on the referenced folder with the attacker project's user list. This vulnerability is fixed in 17.3.3 and 17.4.1.
nvd CVSS3.1
9.9
Vulnerability type
CWE-639
Authorization Bypass Through User-Controlled Key
Published: 26 Jun 2026 · Updated: 20 Jul 2026 · First seen: 26 Jun 2026