Executive brief
OpenProject, a web-based project management platform, contained a flaw that could allow an attacker to change a user's password without knowing the original one. This requires the attacker to have already gained access to a user's active session. If successful, the attacker could permanently take over the account, locking out the legitimate user and gaining full access to their project data and communications.
Technical details
A business logic error (CWE-620) exists in OpenProject's password change implementation. By sending a PATCH request to the '/api/v3/users/me' endpoint, an attacker with an active session can bypass the requirement to provide the current password when setting a new one. The attack complexity is rated as high because it requires an active session takeover (e.g., via session hijacking or physical access to a logged-in terminal) as a precondition. Successful exploitation results in account takeover. The issue is resolved in versions 17.3.2 and 17.4.0.
Affected products
- opf OpenProject < 17.3.2, < 17.4.0
Timeline
- 2026-05-13: advisory: GitHub advisory published by maintainers
- 2026-06-26: disclosed: NVD publication date