CVE-2026-23646Patch(openproject / openproject)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openproject openproject systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a session, it was not properly checked if the session belongs to the user. As the ID that is used to identify these session objects use incremental integers, users could iterate requests using `DELETE /my/sessions/:id` and thus unauthenticate other users. Users did not have access to any sensitive information (like browser identifier, IP addresses, etc) of other users that are stored in the session. The problem was patched in OpenProject versions 16.6.5 and 17.0.1. No known workarounds are available as this does not require any permissions or other that can temporarily be disabled.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-488

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openproject

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
openproject

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-10: 1Patch / Workaround · 2026-02-10: 102-10
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Joel B.D.@darkshram
    Patch

    Disponible LibPNG 1.6.55 en ALDOS, corrigiendo vulnerabilidad CVE-2026-23646 vía @darkshram https://www.alcancelibre.org/noticias/disponible-libpng-1-6-55-en-aldos-corrigiendo-vulnerabilidad-cve-2026-23646

    Post summary

    The post announces that LibPNG 1.6.55 is available in ALDOS, fixing CVE-2026-23646, with the update credited to @darkshram.

    0000072
    1.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprojectopenproject---
Appopenprojectopenproject17.0.0--

Explore more