CVE-2026-47193 Details
Description
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.
A vulnerability exists in OpenProject versions prior to 17.3.3 and 17.4.1, where the journal diff endpoint can unintentionally reveal hidden historical field values. This issue arises because the endpoint fails to properly enforce object and field visibility controls, allowing unauthorized access to sensitive information. The vulnerability has been confirmed in OpenProject versions 17.4.0 and 17.3.1.
Users should update to OpenProject versions 17.3.3 or 17.4.1, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 26, 2026CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/opf/openproject/security/advisories/GHSA-f2rx-x2qj-2hgj | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/opf/openproject/security/advisories/GHSA-f2rx-x2qj-2hgj | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenProject | <= 17.3.2 (semver) <= 17.4.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | New CVE Received | [email protected] |
| Jun 26, 2026 | CVE Modified | CISA-ADP |
Volerion