CVE-2026-49355: OpenProject: Private work package data disclosure through single meeting agenda item API
OpenProject is open-source, web-based project management software. Prior to 17.4.0, GET /api/v3/meetings/:meetingid/agendaitems/:agendaitemid discloses private work package data from a linked work package that belongs to a private/inaccessible project. This vulnerability is fixed in 17.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.4.0
Event History
Frequently Asked Questions
Which deployments are affected?
OpenProject instances running versions before 17.4.0 are affected when a meeting agenda item is linked to a work package in a private or otherwise inaccessible project.
What level of access is required to exploit this issue?
An attacker needs low-privileged access to the OpenProject API and must be able to request the endpoint for the relevant meeting and agenda item. No user interaction is required.
What is the remediation?
Upgrade OpenProject to version 17.4.0, which fixes the disclosure.