CVE-2026-44734: OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and grouping of any Public cost report in the system without verifying ownership or permission level. An attacker who discovers or guesses a public report's numeric ID can rename or overwrite its filter configuration without any warning to the report's owner. This vulnerability is fixed in 17.3.2 and 17.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.3.2 - Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44734?
The severity of CVE-2026-44734 is medium, rated at 6.5 on the CVSS scale.
How do I fix CVE-2026-44734?
To fix CVE-2026-44734, upgrade OpenProject to version 17.3.2 or later.
What does CVE-2026-44734 affect?
CVE-2026-44734 affects versions of OpenProject prior to 17.3.2 and 17.4.0.
What type of vulnerability is CVE-2026-44734?
CVE-2026-44734 is an improper access control vulnerability in the CostReportsController of OpenProject.
Who can exploit CVE-2026-44734?
Any authenticated user can exploit CVE-2026-44734 to modify public cost report details.