CVE-2026-27723: OpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projects
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belonging to unpermitted projects through an improperly authenticated request. This issue has been patched in versions 17.0.5 and 17.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27723?
CVE-2026-27723 has a moderate severity due to insufficient access control in OpenProject.
How do I fix CVE-2026-27723?
To fix CVE-2026-27723, update OpenProject to version 17.0.5 or 17.1.2 or later.
What types of projects are affected by CVE-2026-27723?
CVE-2026-27723 affects OpenProject instances where access control is misconfigured, allowing the creation of wiki pages for unpermitted projects.
What are the potential impacts of CVE-2026-27723?
The potential impacts of CVE-2026-27723 include unauthorized access to project resources and the creation of misleading or harmful wiki content.
Which versions of OpenProject are vulnerable to CVE-2026-27723?
Versions of OpenProject prior to 17.0.5 and 17.1.2 are vulnerable to CVE-2026-27723.