CVE-2026-44733: OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation flaw in the change password behavior allows attackers to change a user's password only with an active session takeover. This vulnerability is fixed in 17.3.2 and 17.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.3.2 - Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44733?
CVE-2026-44733 has a medium severity rating of 5.9.
How can I mitigate CVE-2026-44733?
To mitigate CVE-2026-44733, update OpenProject to versions 17.3.2 or 17.4.0 or later.
What is the impact of CVE-2026-44733?
CVE-2026-44733 allows attackers to bypass password requirements when changing user passwords.
What versions of OpenProject are affected by CVE-2026-44733?
CVE-2026-44733 affects versions of OpenProject prior to 17.3.2 and 17.4.0.
What type of vulnerability is CVE-2026-44733?
CVE-2026-44733 is categorized as a business logic error in OpenProject.