PT-2026-2223 · Openproject · Openproject

Александр Татаринцев

·

Publicado

2026-01-10

·

Atualizado

2026-01-12

·

CVE-2026-22603

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 16.6.2
Description OpenProject is a web-based project management software. The unauthenticated password-change endpoint, /account/change password, lacked the brute-force protection present in the standard login process in affected versions. An attacker capable of guessing or enumerating user IDs could submit an unlimited number of password-change requests for a specific account without triggering account lockout or rate limiting. This enables automated password guessing, potentially leading to full account compromise and possible privilege escalation within the application. The user ID is a critical component in exploiting this issue.
Recommendations Versions prior to 16.6.2 should be upgraded to version 16.6.2 or later. If upgrading is not immediately possible, apply the manual patch.

Exploit

Correção

LPE

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22603
GHSA-93X5-PRX9-X239

Produtos afetados

Openproject