CVE-2026-52784: OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]"
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST parameter "user[admin]". This vulnerability is fixed in 17.3.3 and 17.4.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.3.3 - Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-52784?
The severity of CVE-2026-52784 is high, with a score of 8.8.
How do I fix CVE-2026-52784?
CVE-2026-52784 can be fixed by upgrading to OpenProject versions 17.3.3 or 17.4.1 or later.
What type of vulnerability is CVE-2026-52784?
CVE-2026-52784 is a Cross-Site Request Forgery (CSRF) vulnerability.
What does CVE-2026-52784 affect?
CVE-2026-52784 affects OpenProject prior to versions 17.3.3 and 17.4.1.
Is there a workaround for CVE-2026-52784?
There is no official workaround for CVE-2026-52784; upgrading to a fixed version is necessary.