CVE-2026-27723

Source
https://cve.org/CVERecord?id=CVE-2026-27723
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27723.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27723
Aliases
  • GHSA-9gc6-3xjq-pwc9
Published
2026-03-05T16:26:39.752Z
Modified
2026-04-02T13:21:41.041492Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
OpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projects
Details

OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belonging to unpermitted projects through an improperly authenticated request. This issue has been patched in versions 17.0.5 and 17.1.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27723.json",
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

Git / github.com/opf/openproject

Affected ranges

Type
GIT
Repo
https://github.com/opf/openproject
Events

Affected versions

v17.*
v17.0.4
v17.0.5
v17.1.0
v17.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27723.json"