CVE-2026-52783Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and every userless-OAuth call site (see Write cadence). None of the three allowed cache backends (file_store, memcache, redis) encrypts at rest. An attacker with read access to the cache backend recovers the Azure-AD application-tier bearer with an anonymous get over the memcached binary protocol (or the equivalent against Redis). This vulnerability is fixed in 17.3.3 and 17.4.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-313

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-26: 206-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-52783 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless O… https://www.cve.org/CVERecord?id=CVE-2026-52783 ----- Traducción: CVE-2026-52783 Ope… http://infoflow.cloud`

    Post summary

    The tweet merely announces CVE-2026-52783 affecting OpenProject versions prior to 17.3.3 and 17.4.1, without references to PoC, exploits, patches, or active attacks.

    0001037
    89 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-52783 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless O… https://www.cve.org/CVERecord?id=CVE-2026-52783

    Post summary

    The text cites CVE‑2026‑52783 and notes affected OpenProject releases but does not provide further technical, exploitation, or patch details.

    00000796
    57.7K followersView on X

Explore more