


Perceptive Security
SOC/SIEM Consultancy

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authe…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 21:05:50
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Identity & Access
A vulnerability in OpenProject prior to version 17.6.0 allows authenticated users with edit_work_packages permission but without manage_file_links permission to abuse the PATCH /api/v3/work_packages/{id} API endpoint. Attackers can resolve Storages::FileLink records by raw ID, detach or hard-delete existing FileLinks, and re-parent FileLinks from other projects to an attacker-controlled work package. This improper authorization flaw exposes sensitive metadata including origin filename, origin ID, and MIME type. The vulnerability stems from insufficient permission checks on the _links.fileLinks field accepted by the API. A fix has been released in OpenProject version 17.6.0. The issue is tracked as CVE-2026-67527 and documented in GitHub security advisory GHSA-c6rc-4288-8p4f.
Technical details
Mitigation steps:
Affected products:
OpenProject
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67527
https://github.com/opf/openproject/commit/db480bdeb8802e3d33e4448bb4e4b56a01de2e1f
https://github.com/opf/openproject/pull/23815
https://github.com/opf/openproject/releases/tag/v17.6.0
https://github.com/opf/openproject/security/advisories/GHSA-c6rc-4288-8p4f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
