CVE-2026-40896
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/04/2026
Last modified:
23/04/2026
Description
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project can inject agenda items into meetings belonging to any other project on the instance — even projects they have no access to. No knowledge of the target project, meeting, or victim is required; the attacker can blindly spray items into every meeting on the instance by iterating sequential section IDs. Version 17.3.0 patches the issue.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* | 17.3.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



