CVE-2026-67527 Details
Description
OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve Storages::FileLink records by raw id, detach or hard-delete existing FileLinks, and re-parent FileLinks from other projects to an attacker-controlled work package, exposing origin filename, origin id, and MIME type metadata. This issue is fixed in 17.6.0.
A vulnerability exists in OpenProject, an open-source project management software, prior to version 17.6.0. The issue arises in the Work Packages API, specifically in the PATCH method for updating file links. The vulnerability allows authenticated users with the 'edit_work_packages' permission, but without 'manage_file_links' or membership in the project, to manipulate file links inappropriately. Exploitation involves detaching and permanently deleting file links from work packages, and reassigning file links from other projects to work packages under the attacker's control, thereby accessing and potentially misusing associated metadata.
Users are advised to update OpenProject to version 17.6.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/opf/openproject/commit/db480bdeb8802e3d33e4448bb4e4b56a01de2e1f | [email protected] | Source CodeVendor |
| https://github.com/opf/openproject/pull/23815 | [email protected] | Issue TrackingSource CodeVendor |
| https://github.com/opf/openproject/releases/tag/v17.6.0 | [email protected] | Release NotesVendor |
| https://github.com/opf/openproject/security/advisories/GHSA-c6rc-4288-8p4f | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenProject | < 17.6.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
Volerion