
CVE-2026-40896 OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project can inject agenda i… https://www.cve.org/CVERecord?id=CVE-2026-40896
Post summary
The snippet announces a new CVE in OpenProject, detailing an injection vulnerability tied to manage_agendas permission, but offers no PoC, exploit code, active usage reports, or patch information.

