CVE-2026-30236Disclosure(openproject / openproject)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and planning the labor cost, it was not checked that the user that was planned in the budget is actually a project member. This exposed the user's default rate (if one was set up) to users that should only see that information for project members. Also, the endpoint that handles the pre-calculation for the frontend to display a preview of the costs, while it was being entered, did not properly validate the membership of the user as well. This also allowed to calculate costs with the default rate of non-members. This vulnerability is fixed in 17.2.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openproject

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
openproject

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-13: 203-13
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-30236 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and planning the labor cost, it was not checked t… https://www.cve.org/CVERecord?id=CVE-2026-30236 ----- Traducción: CVE-2026-30236 Ope… http://infoflow.cloud`

    Post summary

    The post simply links to the CVE record for CVE-2026-30236 without providing additional details, claims, or technical information.

    0000030
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30236 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and planning the labor cost, it was not checked t… https://www.cve.org/CVERecord?id=CVE-2026-30236

    Post summary

    A CVE record (CVE-2026-30236) for OpenProject notes an issue with unchecked input when editing project budgets before version 17.2.0.

    00000937
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprojectopenproject---

Explore more