← Vulnerability feed

Vulnerability record · CVE-2026-33667 · published 15 April 2026

CVE-2026-33667: Openproject improper restriction of authentication attempts vulnerability

Openproject · Openproject

OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tracking. The existing brute_force_block_after_failed_logins setting only counts password login failures and does not apply to the 2FA verification stage, and neither the fail_login nor stage_failure methods increment any counter, lock the account, or add any delay. With the default TOTP drift window of ±60 seconds allowing approximately 5 valid codes at any time, an attacker who knows a user's password can brute-force the 6-digit TOTP code at roughly 5-10 attempts per second with an expected completion time of approximately 11 hours. The same vulnerability applies to backup code verification. This effectively allows complete 2FA bypass for any account where the password is known. This issue has been fixed in version 17.3.0.

7.4 CVSS 3.1 High EPSS 0.40% · top 68.1% CWE-307 · Improper restriction of authentication attempts
7.4CVSS 3.1 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tracking. The existing brute_force_block_after_failed_logins setting only counts password login failures and does not apply to the 2FA verification stage, and neither the fail_login nor stage_failure methods increment any counter, lock the account, or add any delay. With the default TOTP drift window of ±60 seconds allowing approximately 5 valid codes at any time, an attacker who knows a user's password can brute-force the 6-digit TOTP code at roughly 5-10 attempts per second with an expected completion time of approximately 11 hours. The same vulnerability applies to backup code verification. This effectively allows complete 2FA bypass for any account where the password is known. This issue has been fixed in version 17.3.0.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33667 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25763Openproject os command injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis…EPSS 0.68%9.4CVE-2026-24685Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability …EPSS 0.36%9.1CVE-2026-22600Openproject information exposure vulnerabilityOpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun…EPSS 0.31%9.0CVE-2026-24772Openproject insufficient verification of data authenticity vulnerabilityOpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced…EPSS 0.19%8.8CVE-2021-43830Openproject sql injection vulnerabilityOpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For a…EPSS 0.93%8.6CVE-2026-22601Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut…EPSS 0.37%8.1CVE-2026-34717Openproject sql injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat…EPSS 0.45%8.1CVE-2019-11600OpenProject activities API SQL injection via id parameterOpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQ…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2026-33667), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.