Junglewise Threat Intelligence

CVE-2026-44732: OpenProject authorization bypass in document update endpoint

CVE-2026-44732 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Technologies: Opf OpenProject.

Executive brief

OpenProject, an open-source project management platform, contains a security flaw in how it handles document updates. An authorized user can bypass intended restrictions to move or modify documents belonging to projects they do not have permission to manage. This could lead to unauthorized changes to project documentation and organizational data being moved to incorrect project folders.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the OpenProject document update endpoint (/api/v3/documents/{id}). The root cause is an improper authorization sequence where attacker-controlled attributes are applied to a persisted record before final authorization checks are enforced. By sending a PATCH request with a modified 'project_id' parameter, an authenticated user lacking the ':manage_documents' permission can successfully move and modify documents across different projects. This allows for unauthorized modification of resources. The issue is resolved in versions 17.3.2 and 17.4.0.

Affected products

  • opf OpenProject < 17.3.2, < 17.4.0

Timeline

  • 2026-05-13: advisory: Original GitHub advisory published
  • 2026-06-26: disclosed: NVD publication date
  • 2026-06-26: patched: Fix confirmed in versions 17.3.2 and 17.4.0

References