PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44735 opf CVE debrief

CVE-2026-44735 is a vulnerability in OpenProject, an open-source, web-based project management software. The issue arises from the GET /api/v3/shares endpoint, which returns share details for all work packages in a project to any user with the view_shared_work_packages permission. However, the authorization check only operates at the project level and does not verify if the requesting user can view each individual shared work package. This allows regular project members to discover work package IDs, subjects (including confidential titles), and the role levels assigned (Editor, Commenter, Viewer) for work packages they have been granted shared access to. The vulnerability is fixed in OpenProject versions 17.3.2 and 17.4.0.

Vendor
opf
Product
openproject
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-26
Original CVE updated
2026-06-29
Advisory published
2026-06-26
Advisory updated
2026-06-29

Who should care

Users of OpenProject, specifically those with administrative privileges or those responsible for security within projects that utilize OpenProject for project management, should be aware of this vulnerability. Given the medium severity and the potential for information disclosure, it's crucial for these users to assess their exposure and apply the necessary patches.

Technical summary

The vulnerability in OpenProject's GET /api/v3/shares endpoint allows unauthorized disclosure of work package details to users with the view_shared_work_packages permission. This includes work package IDs, subjects, and role levels without proper authorization checks at the individual work package level. The CVSS score for this vulnerability is 6.5, classified as MEDIUM severity. The issue is addressed in OpenProject versions 17.3.2 and 17.4.0.

Defensive priority

Applying patches to update OpenProject to version 17.3.2 or 17.4.0 is of high priority to mitigate the risk of information disclosure. Additionally, reviewing project member permissions and ensuring that the principle of least privilege is enforced can help reduce the potential impact.

Recommended defensive actions

  • Update OpenProject to version 17.3.2 or 17.4.0 to patch the vulnerability.
  • Review and adjust project member permissions to ensure the principle of least privilege.
  • Monitor project activity for any unauthorized access attempts.
  • Consider implementing additional logging and monitoring to detect potential exploitation attempts.
  • Inform project members about the vulnerability and the importance of applying patches.

Evidence notes

The CVE-2026-44735 entry and details were sourced from the National Vulnerability Database (NVD) and the Common Vulnerabilities and Exposures (CVE) list. The vulnerability was disclosed by the OpenProject team through their security advisory process.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44735 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44735

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44735 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44735

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.