OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3.
References
| Link | Resource |
|---|---|
| https://github.com/opf/openproject/releases/tag/v16.6.3 | Release Notes |
| https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-01-10 02:15
Updated : 2026-01-14 22:27
NVD link : CVE-2026-22605
Mitre link : CVE-2026-22605
CVE.ORG link : CVE-2026-22605
JSON object : View
Products Affected
openproject
- openproject
CWE
CWE-284
Improper Access Control
