MEDIUM

CVE-2026-44736

2026-06-26 CVSS v3.1
CVSS
6.5

Description

OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary work package ID in the involved, fromId, or toId filter. This bypasses the Relation.visible scope due to a flawed performance optimization in RelationQuery. This vulnerability is fixed in 17.4.0.

Summary dbcve.org

The GET /api/v3/relations endpoint in OpenProject versions prior to 17.4.0 allows any authenticated user to access work package subjects (titles) they lack permission to view by supplying arbitrary work package IDs in the involved, fromId, or toId filter parameters. The vulnerability stems from a flawed performance optimization in RelationQuery that bypasses the Relation.visible permission scope.

Mitigation

Upgrade OpenProject to version 17.4.0 or later to apply the fix that properly enforces the Relation.visible permission scope.

Weakness (CWE)

CWE-200 Information Exposure
CWE-639 Authorization Bypass (IDOR)
CWE-836

EPSS Score

0.39%
Probability of exploitation in next 30 days
33.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE