CVE-2026-27723

OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belonging to unpermitted projects through an improperly authenticated request. This issue has been patched in versions 17.0.5 and 17.1.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-05 19:16

Updated : 2026-03-10 18:21


NVD link : CVE-2026-27723

Mitre link : CVE-2026-27723

CVE.ORG link : CVE-2026-27723


JSON object : View

Products Affected

openproject

  • openproject
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo