CVE-2026-44736
Description
OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary work package ID in the involved, fromId, or toId filter. This bypasses the Relation.visible scope due to a flawed performance optimization in RelationQuery. This vulnerability is fixed in 17.4.0.
Summary dbcve.org
The GET /api/v3/relations endpoint in OpenProject versions prior to 17.4.0 allows any authenticated user to access work package subjects (titles) they lack permission to view by supplying arbitrary work package IDs in the involved, fromId, or toId filter parameters. The vulnerability stems from a flawed performance optimization in RelationQuery that bypasses the Relation.visible permission scope.
Mitigation
Upgrade OpenProject to version 17.4.0 or later to apply the fix that properly enforces the Relation.visible permission scope.