CVE-2026-52785: OpenProject: SQL injection in timestamps functionality
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This vulnerability is fixed in 17.3.3 and 17.4.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.3.3 - Upgrade
Upgrade
OpenProjectto a version that resolves this vulnerability.Fixed in 17.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-52785?
The severity of CVE-2026-52785 is critical with a score of 9.9.
How do I fix CVE-2026-52785?
To fix CVE-2026-52785, upgrade OpenProject to versions 17.3.3 or 17.4.1 and later.
What is the impact of CVE-2026-52785?
CVE-2026-52785 allows for SQL injection attacks through the timestamps functionality, potentially exposing sensitive data.
Which versions of OpenProject are affected by CVE-2026-52785?
Versions prior to OpenProject 17.3.3 and 17.4.1 are affected by CVE-2026-52785.
How does CVE-2026-52785 affect data integrity in OpenProject?
CVE-2026-52785 can lead to unauthorized modifications or retrieval of data in the OpenProject application, compromising data integrity.