Junglewise Threat Intelligence

CVE-2026-52784: OpenProject CSRF privilege escalation in user management endpoint

CVE-2026-52784 · Severity: high · CVSS 8.8 · Published 2026-06-26

Technologies: Opf OpenProject.

Executive brief

OpenProject is a web-based project management platform used for team collaboration and task tracking. A security flaw allows an attacker to trick the system into granting administrative privileges to a user account without the victim's knowledge. This could lead to a full takeover of the project management environment and unauthorized access to sensitive corporate data.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in OpenProject's user management component. The flaw stems from how Turbo Drive auto-injects CSRF tokens into forms appended via Turbo Stream actions, combined with a 'dispatch_event' action that can trigger an automatic form submission. An attacker can exploit this by sending a malicious payload to the '/users/:id' endpoint using the 'user[admin]' POST parameter. Successful exploitation allows a low-privileged user to elevate their own or another user's privileges to administrator. The vulnerability is addressed in versions 17.3.3 and 17.4.1.

Affected products

  • opf OpenProject < 17.3.3, >= 17.4.0 < 17.4.1

Timeline

  • 2026-06-08: advisory: GitHub advisory published by vendor
  • 2026-06-26: disclosed: NVD publication date
  • 2026-06-26: patched: Fixes confirmed in versions 17.3.3 and 17.4.1

References