CVE-2026-24772Patch(openproject / openproject)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openproject openproject systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronization server. The OpenPrioject backend generates an authentication token that is currently valid for 24 hours, encrypts it with a shared secret only known to the synchronization server. The frontend hands this encrypted token and the backend URL over to the synchronization server to check user's ability to work on the document and perform intermittent saves while editing. The synchronization server does not properly validate the backend URL and sends a request with the decrypted authentication token to the endpoint that was given to the server. An attacker could use this vulnerability to decrypt a token that he intercepted by other means to gain an access token to interact with OpenProject on the victim's behalf. This vulnerability was introduced with OpenProject 17.0.0 and was fixed in 17.0.2. As a workaround, disable the collaboration feature via Settings -> Documents -> Real time collaboration -> Disable. Additionally the `hocuspocus` container should also be disabled.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openproject

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
openproject

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-28: 2Mentions · 2026-01-30: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 101-2801-30
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-282
General1Patch1
2026-01-301
Patch1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Patch

    OpenProject is affected by SSRF and CSWSH in its Hocuspocus Synchronization Server (CVE-2026-24772). Upgrade to version 17.0.2. #OpenProject #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-24772-openproject-ssrf-cswsh

    Post summary

    OpenProject is vulnerable to SSRF and CSWSH in its Hocuspocus Synchronization Server (CVE‑2026‑24772). Users should upgrade to version 17.0.2 to address the issue.

    0000057
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24772: HIGH] OpenProject 17.0 introduced a synchronization server for real-time collaboration. A vulnerability allowed attackers to intercept authentication tokens. Mitigate by disabling collaborat...#cve,CVE-2026-24772,#cybersecurity https://cvefind.com/CVE-2026-24772

    Post summary

    The post announces CVE‑2026‑24772, explains it allows attackers to intercept authentication tokens in OpenProject 17.0, and provides a workaround of disabling the collaboration feature.

    0000043
    584 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24772 OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronizatio… https://www.cve.org/CVERecord?id=CVE-2026-24772

    Post summary

    The provided text merely states the existence of CVE-2026-24772 and offers a link to the CVE record, without any further detail on the vulnerability, exploitation, or remediation.

    00000170
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprojectopenproject---

Explore more