O
penProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3.
References
| Link | Resource |
|---|---|
| https://github.com/opf/openproject/releases/tag/v16.6.3 | Release Notes |
| https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j | Patch Vendor Advisory |
Configurations
History
14 Jan 2026, 22:27
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* | |
| References | () https://github.com/opf/openproject/releases/tag/v16.6.3 - Release Notes | |
| References | () https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j - Patch, Vendor Advisory | |
| First Time |
Openproject openproject
Openproject |
10 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-10 02:15
Updated : 2026-01-14 22:27
NVD link : CVE-2026-22605
Mitre link : CVE-2026-22605
CVE.ORG link : CVE-2026-22605
JSON object : View
Products Affected
CWE
CWE-284
Improper Access Control