← Vulnerability feed

Vulnerability record · CVE-2026-24772 · published 28 January 2026

CVE-2026-24772: Openproject insufficient verification of data authenticity vulnerability

Openproject · Openproject

OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronization server. The OpenPrioject backend generates an authentication token that is currently valid for 24 hours, encrypts it with a shared secret only known to the synchronization server. The frontend hands this encrypted token and the backend URL over to the synchronization server to check user's ability to work on the document and perform intermittent saves while editing. The synchronization server does not properly validate the backend URL and sends a request with the decrypted authentication token to the endpoint that was given to the server. An attacker could use this vulnerability to decrypt a token that he intercepted by other means to gain an access token to interact with OpenProject on the victim's behalf. This vulnerability was introduced with OpenProject 17.0.0 and was fixed in 17.0.2. As a workaround, disable the collaboration feature via Settings -> Documents -> Real time collaboration -> Disable. Additionally the `hocuspocus` container should also be disabled.

9.0 CVSS 3.1 Critical EPSS 0.19% · top 92.7% CWE-345 · Insufficient verification of data authenticity
9.0CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronization server. The OpenPrioject backend generates an authentication token that is currently valid for 24 hours, encrypts it with a shared secret only known to the synchronization server. The frontend hands this encrypted token and the backend URL over to the synchronization server to check user's ability to work on the document and perform intermittent saves while editing. The synchronization server does not properly validate the backend URL and sends a request with the decrypted authentication token to the endpoint that was given to the server. An attacker could use this vulnerability to decrypt a token that he intercepted by other means to gain an access token to interact with OpenProject on the victim's behalf. This vulnerability was introduced with OpenProject 17.0.0 and was fixed in 17.0.2. As a workaround, disable the collaboration feature via Settings -> Documents -> Real time collaboration -> Disable. Additionally the `hocuspocus` container should also be disabled.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-24772 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25763Openproject os command injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis…EPSS 0.68%9.4CVE-2026-24685Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability …EPSS 0.36%9.1CVE-2026-22600Openproject information exposure vulnerabilityOpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun…EPSS 0.31%8.8CVE-2021-43830Openproject sql injection vulnerabilityOpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For a…EPSS 0.93%8.6CVE-2026-22601Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut…EPSS 0.37%8.1CVE-2026-34717Openproject sql injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat…EPSS 0.45%8.1CVE-2019-11600OpenProject activities API SQL injection via id parameterOpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQ…EPSS 80%analysed8.1CVE-2017-11667Openproject insufficient session expiration vulnerabilityOpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leve…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-24772), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.