PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67528 opf CVE debrief

Authenticated non-admin users could enumerate sequential custom option ids and read labels belonging to admin_only user or group custom fields in OpenProject prior to 17.6.0. This vulnerability allows potential enumeration and information disclosure, impacting OpenProject administrators and users with custom option configurations. It is recommended to verify the OpenProject version and apply the patch if necessary, restrict access to custom option IDs for non-admin users, and monitor for suspicious enumeration attempts. The issue was fixed in OpenProject 17.6.0.

Vendor
opf
Product
openproject
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

OpenProject administrators and users with custom option configurations, as well as security teams monitoring for potential enumeration attacks, should be aware of this vulnerability. They should verify their OpenProject version and apply the patch if necessary. Additionally, they should restrict access to custom option IDs for non-admin users and monitor for suspicious enumeration attempts.

Technical summary

CVE-2026-67528 is a vulnerability in OpenProject that allows authenticated non-admin users to enumerate sequential custom option IDs and read labels belonging to admin-only user or group custom fields. The issue was fixed in OpenProject 17.6.0. To mitigate, verify OpenProject version and apply the patch if vulnerable. Restrict access to custom option IDs for non-admin users and monitor for suspicious enumeration attempts.

Defensive priority

Medium priority due to the CVSS score of 4.3 and the potential for enumeration and information disclosure.

Recommended defensive actions

  • Verify OpenProject version and apply patch 17.6.0 if vulnerable
  • Restrict access to custom option IDs for non-admin users
  • Monitor for suspicious enumeration attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and NVD detail provide information about the vulnerability in OpenProject, but further analysis is limited by the available data. Verification of the vulnerability and its impact is recommended. To verify, review the official advisory and CVE record for affected scope, severity, and vendor guidance. Check relevant monitoring, detection, and logs for exposed assets that need extra review. The vulnerability allows authenticated non-admin users to enumerate sequential custom option IDs and read labels belonging to admin-only user or group custom fields. This issue was fixed in OpenProject 17.6.0.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T20:18:14.613Z and has not been modified since then.