PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52783 opf CVE debrief

CVE-2026-52783 is a high-severity vulnerability in OpenProject's Storages module. Prior to versions 17.3.3 and 17.4.1, the module writes OneDrive/SharePoint userless OAuth access tokens in plaintext to Rails.cache. The tokens are continuously repopulated by an hourly cron job and every userless-OAuth call site. Since none of the three allowed cache backends (file_store, memcache, redis) encrypts data at rest, an attacker with read access to the cache backend can recover the Azure-AD application-tier bearer token via an anonymous get request over the memcached binary protocol or equivalent methods for Redis. This vulnerability has been fixed in OpenProject versions 17.3.3 and 17.4.1.

Vendor
opf
Product
openproject
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-26
Original CVE updated
2026-06-29
Advisory published
2026-06-26
Advisory updated
2026-06-29

Who should care

Organizations using OpenProject versions prior to 17.3.3 or 17.4.1 should prioritize patching this vulnerability. Specifically, those with integrations to OneDrive or SharePoint via the Storages module are at risk. Security teams responsible for monitoring and protecting against unauthorized access to sensitive data should be aware of this issue.

Technical summary

The OpenProject Storages module, prior to versions 17.3.3 and 17.4.1, stores OneDrive/SharePoint userless OAuth access tokens in plaintext within Rails.cache. These tokens are used for authentication with Azure-AD. The cache is updated hourly by a cron job and with every userless-OAuth call. Since the cache backends (file_store, memcache, redis) do not encrypt data at rest, an attacker with read access to the cache can retrieve these tokens. With these tokens, an attacker can impersonate the Azure-AD application, potentially leading to unauthorized access to sensitive data.

Defensive priority

High. Immediate patching to versions 17.3.3 or 17.4.1 is recommended to prevent exposure of sensitive OAuth tokens.

Recommended defensive actions

  • Apply patches to OpenProject versions 17.3.3 or 17.4.1.
  • Review and update cache backend configurations to use encryption at rest if possible.
  • Monitor for suspicious activity related to OAuth token usage.
  • Perform a thorough inventory check of OpenProject installations and their integrations.
  • Implement compensating controls such as additional monitoring and access restrictions.

Evidence notes

The CVE-2026-52783 details were sourced from the official CVE record and the OpenProject security advisory. The vulnerability's high severity stems from the exposure of sensitive OAuth tokens without encryption. Evidence from the source indicates that fixes are available in OpenProject versions 17.3.3 and 17.4.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52783 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52783

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52783 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52783

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.