Junglewise Threat Intelligence

CVE-2026-52779: OpenProject IDOR in Calendar and Team Planner modules

CVE-2026-52779 · Severity: medium · CVSS 5.4 · Published 2026-06-26

Technologies: Opf OpenProject.

Executive brief

OpenProject, an open-source project management platform, was found to have a security flaw in its Calendar and Team Planner modules. This vulnerability allows a user who has management permissions in one project to delete shared or public views in a completely different project where they lack such permissions. This could lead to the loss of important shared project schedules and planning views, disrupting team operations and data integrity.

Technical details

A cross-project IDOR / authorization context confusion exists in the Calendar and Team Planner modules of OpenProject. The application performs project-based authorization using the ':project_id' provided in the URL, but subsequently loads the target 'Query' object by its ':id' without verifying that the object actually belongs to the authorized project. An attacker with management permissions in 'Project A' can send a DELETE request referencing 'Project A' in the URL while targeting the ID of a public Calendar or Team Planner view belonging to 'Project B'. This allows the attacker to bypass intended permission boundaries and delete shared views they do not own. The issue is fixed in versions 17.3.3 and 17.4.1.

Affected products

  • opf OpenProject < 17.3.3, >= 17.4.0 < 17.4.1

Timeline

  • 2026-06-10: advisory: Original GitHub security advisory published
  • 2026-06-26: disclosed: NVD publication date

References