cvedb.io
CVE-2026-27723
MEDIUM · CVSS 4.3
EPSS exploitation probability: 0%
Published 2026-03-05T19:16:05.660 · Last modified 2026-06-17T10:27:33.710

Summary

OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belonging to unpermitted projects through an improperly authenticated request. This issue has been patched in versions 17.0.5 and 17.1.2.

Affected products

openproject — openproject

Does this affect you?

Add your gear to cvedb and we'll alert you only when openproject ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.