CVE-2026-22605

O

penProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3.

Configurations

Configuration 1 (hide)

cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*

History

14 Jan 2026, 22:27

Type Values Removed Values Added
CPE cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*
References () https://github.com/opf/openproject/releases/tag/v16.6.3 - () https://github.com/opf/openproject/releases/tag/v16.6.3 - Release Notes
References () https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j - () https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j - Patch, Vendor Advisory
First Time Openproject openproject
Openproject

10 Jan 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-10 02:15

Updated : 2026-01-14 22:27


NVD link : CVE-2026-22605

Mitre link : CVE-2026-22605

CVE.ORG link : CVE-2026-22605


JSON object : View

Products Affected
CWE
CWE-284

Improper Access Control