OpenProject, an open-source project management platform, is affected by a critical IDOR vulnerability (CVE-2026-52782) with a CVSS score of 9.9. This issue arises from improper access control in the /projects/<A>/settings/project_storages/<A_ps_id> endpoint when processing the PATCH parameter 'storages_project_storage[project_folder_id]'. An attacker with project-admin privileges in one project can modify storage configurations to access unauthorized resources, specifically hijacking Nextcloud or OneDrive folders managed by other projects on the same storage. This allows the attacker to overwrite ACLs on target folders, granting unauthorized access. The vulnerability impacts all versions prior to 17.3.3 and 17.4.1. Organizations using OpenProject with integrated cloud storage should prioritize applying the latest patches to mitigate this risk. Immediate remediation is advised to prevent unauthorized data access and potential data breaches.
CRITICAL
CVSS 9.9
CVE-2026-52782
2026-08-22
CVE-2026-52782: Critical IDOR Vulnerability in OpenProject Allows Resource Hijacking
A critical IDOR vulnerability in OpenProject (CVE-2026-52782) allows project-admins to hijack storage folders of other projects. CVSS 9.9. Affected versions: prior to 17.3.3 and 17.4.1. Patching is strongly recommended.