CVE-2026-44731Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all existing user accounts by probing user IDs and observing differences in the server response. This vulnerability is fixed in 17.3.2 and 17.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-27: 2Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-27: 206-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-44731 OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given use… https://www.cve.org/CVERecord?id=CVE-2026-44731 ----- Traducción: CVE-2026-44731 Ope… http://infoflow.cloud`

    Post summary

    CVE-2026-44731 is disclosed for OpenProject versions before 17.3.2 and 17.4.0, highlighting a data leakage via the meetings filter feature; no exploit, PoC, or patch details are provided.

    0001039
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44731 OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given use… https://www.cve.org/CVERecord?id=CVE-2026-44731

    Post summary

    CVE‑2026‑44731 is an information‑disclosure flaw in OpenProject’s meetings filter that existed before versions 17.3.2 and 17.4.0, which are implied to contain the fix.

    000001.1K
    57.7K followersView on X

Explore more