CVE-2026-40896: OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with manageagendas permission in any project can inject agenda items into meetings belonging to any other project on the instance — even projects they have no access to. No knowledge of the target project, meeting, or victim is required; the attacker can blindly spray items into every meeting on the instance by iterating sequential section IDs. Version 17.3.0 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40896?
CVE-2026-40896 has a medium severity rating due to its potential impact on project confidentiality and integrity.
How do I fix CVE-2026-40896?
To fix CVE-2026-40896, upgrade OpenProject to version 17.3.0 or later where the vulnerability has been addressed.
Who is affected by CVE-2026-40896?
Any OpenProject user with 'manage_agendas' permission prior to version 17.3.0 is affected by CVE-2026-40896.
What type of vulnerability is CVE-2026-40896?
CVE-2026-40896 is categorized as a Cross-Project Meeting Agenda Item Injection vulnerability.
Can CVE-2026-40896 lead to unauthorized access?
Yes, CVE-2026-40896 can allow a user to inject agenda items into meetings of other projects, potentially leading to unauthorized access to sensitive information.