A critical SQL injection vulnerability, designated CVE-2026-52785, affects OpenProject versions prior to 17.3.3 and 17.4.1. The vulnerability exists in the timestamps functionality, where the baseline comparison feature allows attackers to request historic work-package attributes using the timestamps parameter. This could enable malicious actors to execute arbitrary SQL commands, leading to unauthorized data access, modification, or deletion. The CVSS score of 9.9 reflects the high severity of this issue. All users of OpenProject versions before the specified patches are advised to upgrade immediately to mitigate the risk. The vulnerability has been addressed in versions 17.3.3 and 17.4.1. Organizations should conduct an inventory of affected systems and apply the necessary updates to prevent exploitation. No evidence of active exploitation has been reported, but the potential impact warrants urgent action.