PatchSiren cyber security CVE debrief
CVE-2026-67528 opf CVE debrief
Authenticated non-admin users could enumerate sequential custom option ids and read labels belonging to admin_only user or group custom fields in OpenProject prior to 17.6.0. This vulnerability allows potential enumeration and information disclosure, impacting OpenProject administrators and users with custom option configurations. It is recommended to verify the OpenProject version and apply the patch if necessary, restrict access to custom option IDs for non-admin users, and monitor for suspicious enumeration attempts. The issue was fixed in OpenProject 17.6.0.
- Vendor
- opf
- Product
- openproject
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-07-31
Who should care
OpenProject administrators and users with custom option configurations, as well as security teams monitoring for potential enumeration attacks, should be aware of this vulnerability. They should verify their OpenProject version and apply the patch if necessary. Additionally, they should restrict access to custom option IDs for non-admin users and monitor for suspicious enumeration attempts.
Technical summary
CVE-2026-67528 is a vulnerability in OpenProject that allows authenticated non-admin users to enumerate sequential custom option IDs and read labels belonging to admin-only user or group custom fields. The issue was fixed in OpenProject 17.6.0. To mitigate, verify OpenProject version and apply the patch if vulnerable. Restrict access to custom option IDs for non-admin users and monitor for suspicious enumeration attempts.
Defensive priority
Medium priority due to the CVSS score of 4.3 and the potential for enumeration and information disclosure.
Recommended defensive actions
- Verify OpenProject version and apply patch 17.6.0 if vulnerable
- Restrict access to custom option IDs for non-admin users
- Monitor for suspicious enumeration attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record and NVD detail provide information about the vulnerability in OpenProject, but further analysis is limited by the available data. Verification of the vulnerability and its impact is recommended. To verify, review the official advisory and CVE record for affected scope, severity, and vendor guidance. Check relevant monitoring, detection, and logs for exposed assets that need extra review. The vulnerability allows authenticated non-admin users to enumerate sequential custom option IDs and read labels belonging to admin-only user or group custom fields. This issue was fixed in OpenProject 17.6.0.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T20:18:14.613Z and has not been modified since then.