PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67528 opf CVE debrief

Authenticated non-admin users could enumerate sequential custom option ids and read labels belonging to admin_only user or group custom fields in OpenProject prior to 17.6.0. This vulnerability allows potential enumeration and information disclosure, impacting OpenProject administrators and users with custom option configurations. It is recommended to verify the OpenProject version and apply the patch if necessary, restrict access to custom option IDs for non-admin users, and monitor for suspicious enumeration attempts. The issue was fixed in OpenProject 17.6.0.

Vendor
opf
Product
openproject
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

OpenProject administrators and users with custom option configurations, as well as security teams monitoring for potential enumeration attacks, should be aware of this vulnerability. They should verify their OpenProject version and apply the patch if necessary. Additionally, they should restrict access to custom option IDs for non-admin users and monitor for suspicious enumeration attempts.

Technical summary

CVE-2026-67528 is a vulnerability in OpenProject that allows authenticated non-admin users to enumerate sequential custom option IDs and read labels belonging to admin-only user or group custom fields. The issue was fixed in OpenProject 17.6.0. To mitigate, verify OpenProject version and apply the patch if vulnerable. Restrict access to custom option IDs for non-admin users and monitor for suspicious enumeration attempts.

Defensive priority

Medium priority due to the CVSS score of 4.3 and the potential for enumeration and information disclosure.

Recommended defensive actions

  • Verify OpenProject version and apply patch 17.6.0 if vulnerable
  • Restrict access to custom option IDs for non-admin users
  • Monitor for suspicious enumeration attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and NVD detail provide information about the vulnerability in OpenProject, but further analysis is limited by the available data. Verification of the vulnerability and its impact is recommended. To verify, review the official advisory and CVE record for affected scope, severity, and vendor guidance. Check relevant monitoring, detection, and logs for exposed assets that need extra review. The vulnerability allows authenticated non-admin users to enumerate sequential custom option IDs and read labels belonging to admin-only user or group custom fields. This issue was fixed in OpenProject 17.6.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-67528 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-67528

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-67528 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67528

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.