CVE-2026-32698Disclosure(openproject / openproject)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openproject openproject systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was used in a Cost Report, the custom field's name was injected into the SQL query without proper sanitation. This allowed an attacker to execute arbitrary SQL commands during the generation of a Cost Report. As custom fields can only be generated by users with full administrator privileges, the attack surface is somewhat reduced. Together with another bug in the Repositories_module, that used the project identifier without sanitation to generate the checkout path for a git repository in the filesystem, this allowed an attacker to checkout a git repository to an arbitrarily chosen path on the server. If the checkout is done within certain paths within the OpenProject application, upon the next restart of the application, this allows the attacker to inject ruby code into the application. As the project identifier cannot be manually edited to any string containing special characters like dots or slashes, this needs to be changed via the SQL injection described above. Versions 16.6.9, 17.0.6, 17.1.3, and 17.2.1 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openproject

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-19)
  • 5 total mentions across 2 days

Affected systems

Products
openproject

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-18: 2Mentions · 2026-03-19: 3Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 203-1803-19
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1Patch1
2026-03-193
Disclosure3
Full discourse5 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-32698 - opf - openproject - https://www.redpacketsecurity.com/cve-alert-cve-2026-32698-opf-openproject/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32698 #opf #openproject

    Post summary

    The tweet is a brief alert linking to a CVE page for CVE-2026-32698, providing no additional technical information or evidence of exploitation.

    0000073
    3.6K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32698: OpenProject has a SQL Injection ... Admin-only SQLi chaining to RCE through git repo path traversal - classic privilege escalation goldmine for post-exploi... https://zerodaysignal.com/vulnerability/CVE-2026-32698 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the discovery of a new SQL Injection vulnerability in OpenProject that can lead to RCE via admin‑only access and git repo path traversal, but does not provide PoC, exploit code, active exploitation evidence, or patch details.

    0000053
    154 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32698 OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack v… https://www.cve.org/CVERecord?id=CVE-2026-32698

    Post summary

    Vulnerability CVE‑2026‑32698 in OpenProject older than specified versions enables SQL injection; no patch, exploit, or active exploitation was reported in the text.

    00000145
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32698 - Critical OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's n... https://www.thehackerwire.com/vulnerability/CVE-2026-32698/ https://t.co/TVI4mnohlb

    Post summary

    The post announces a critical SQL injection vulnerability (CVE-2026-32698) affecting older OpenProject versions, but provides no exploit code, patches, or evidence of active exploitation.

    0000044
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32698: CRITICAL] OpenProject software had vulnerabilities pre-version 16.6.9, 17.0.6, 17.1.3, and 17.2.1, exposing risks like SQL injection attacks. Update to secure your cyber defense.#cve,CVE-2026-32698,#cybersecurity https://cvefind.com/CVE-2026-32698

    Post summary

    The tweet alerts to a critical SQL injection vulnerability (CVE‑2026‑32698) in OpenProject and urges users to apply security updates to mitigate the risk.

    0000050
    603 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprojectopenproject---
Appopenprojectopenproject17.2.0--

Explore more