PT-2026-5179 · Openproject · Openproject

Syndrome-Impostor

·

Publicado

2026-01-28

·

Atualizado

2026-02-12

·

CVE-2026-24772

CVSS v3.1

9.0

Crítica

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenProject versions 17.0.0 through 17.0.1
Description OpenProject is a web-based project management software. A synchronization server was introduced in version 17.0.0 to enable real-time collaboration on documents. The server does not properly validate the backend URL and sends a request with a decrypted authentication token to the provided endpoint. This allows an attacker who has intercepted an authentication token to gain access to OpenProject on behalf of the victim. The authentication token is valid for 24 hours and is encrypted with a shared secret. The vulnerable functionality involves the interaction between the OpenProject backend, frontend, and synchronization server. The issue was introduced with version 17.0.0.
Recommendations Disable the collaboration feature via Settings -> Documents -> Real time collaboration -> Disable. Disable the hocuspocus container.

Exploit

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24772
GHSA-R854-P5QJ-X974

Produtos afetados

Openproject