PT-2026-5179 · Openproject · Openproject
Syndrome-Impostor
·
Published
2026-01-28
·
Updated
2026-02-12
·
CVE-2026-24772
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenProject versions 17.0.0 through 17.0.1
Description
OpenProject is a web-based project management software. A synchronization server was introduced in version 17.0.0 to enable real-time collaboration on documents. The server does not properly validate the backend URL and sends a request with a decrypted authentication token to the provided endpoint. This allows an attacker who has intercepted an authentication token to gain access to OpenProject on behalf of the victim. The authentication token is valid for 24 hours and is encrypted with a shared secret. The vulnerable functionality involves the interaction between the OpenProject backend, frontend, and synchronization server. The issue was introduced with version 17.0.0.
Recommendations
Disable the collaboration feature via Settings -> Documents -> Real time collaboration -> Disable.
Disable the
hocuspocus container.Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openproject