top of page
perceptive_background_267k.jpg

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authe…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 21:05:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Identity & Access

A vulnerability in OpenProject prior to version 17.6.0 allows authenticated users with edit_work_packages permission but without manage_file_links permission to abuse the PATCH /api/v3/work_packages/{id} API endpoint. Attackers can resolve Storages::FileLink records by raw ID, detach or hard-delete existing FileLinks, and re-parent FileLinks from other projects to an attacker-controlled work package. This improper authorization flaw exposes sensitive metadata including origin filename, origin ID, and MIME type. The vulnerability stems from insufficient permission checks on the _links.fileLinks field accepted by the API. A fix has been released in OpenProject version 17.6.0. The issue is tracked as CVE-2026-67527 and documented in GitHub security advisory GHSA-c6rc-4288-8p4f.

Technical details

Mitigation steps:

Affected products:

OpenProject

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page