CVE-2026-24007 Details
Description
Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This vulnerability is fixed in Tuleap Community Edition 17.0.99.1768924735 and Tuleap Enterprise Edition 17.2-5, 17.1-6, and 17.0-9.
A vulnerability exists in Tuleap's Agile Dashboard Overview, specifically in versions prior to 17.0.99.1768924735 for the Community Edition and earlier than 17.0-9, 17.2-5, and 17.1-6 for the Enterprise Edition. The issue arises from a lack of Cross-Site Request Forgery (CSRF) protection when users attempt to resolve inconsistent items within a milestone overview. This flaw could be exploited to manipulate users into inadvertently repairing these inconsistencies, thereby creating unintended artifact links.
Users can upgrade to Tuleap Community Edition 17.0.99.1768924735 or Tuleap Enterprise Edition 17.2-5, 17.1-6, or 17.0-9 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| enalean tuleap | < 17.0-9 < 17.0.99.1768924735 >= 17.1, < 17.1-6 >= 17.2, < 17.2-5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2026 | Initial Analysis | [email protected] |
| Feb 2, 2026 | New CVE Received | [email protected] |