Junglewise Threat Intelligence

CVE-2026-44733: OpenProject unverified password change in users API

CVE-2026-44733 · Severity: medium · CVSS 5.9 · Published 2026-06-26

Technologies: Opf OpenProject.

Executive brief

OpenProject, a web-based project management platform, contained a flaw that could allow an attacker to change a user's password without knowing the original one. This requires the attacker to have already gained access to a user's active session. If successful, the attacker could permanently take over the account, locking out the legitimate user and gaining full access to their project data and communications.

Technical details

A business logic error (CWE-620) exists in OpenProject's password change implementation. By sending a PATCH request to the '/api/v3/users/me' endpoint, an attacker with an active session can bypass the requirement to provide the current password when setting a new one. The attack complexity is rated as high because it requires an active session takeover (e.g., via session hijacking or physical access to a logged-in terminal) as a precondition. Successful exploitation results in account takeover. The issue is resolved in versions 17.3.2 and 17.4.0.

Affected products

  • opf OpenProject < 17.3.2, < 17.4.0

Timeline

  • 2026-05-13: advisory: GitHub advisory published by maintainers
  • 2026-06-26: disclosed: NVD publication date

References