216.73.216.197

CVE-2026-23721

· Published 19/01/2026 18:16 · Modified 19/01/2026 18:16

Labels: CVE-2026-23721 2026-01-19CVE-2026-23721CWE-862[email protected]

Essential information

Published
19/01/2026 18:16
Modified
19/01/2026 18:16
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

OpenProject is an open-source, web-based project management software. When using groups in OpenProject to manage users, the group members should only be visible to users that have the View Members permission in any project that the group is also a member of. Prior to versions 17.0.1 and 16.6.5, due to a failed permission check, if a user had the View Members permission in any project, they could enumerate all Groups and view which other users are part of the group. The issue has been fixed in OpenProject 17.0.1 and 16.6.5. No known workarounds are available.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openproject / openproject cpe:2.3:a:openproject:openproject:<16.6.5:*:*:*:*:*:*:*
openproject / openproject cpe:2.3:a:openproject:openproject:<17.0.1:*:*:*:*:*:*:*

References