CVE-2026-52785Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This vulnerability is fixed in 17.3.3 and 17.4.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-26); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-26: 2Mentions · 2026-06-27: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-27: 106-2606-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-262
Disclosure2
2026-06-271
Disclosure1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-52785 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject basel… https://www.cve.org/CVERecord?id=CVE-2026-52785 ----- Traducción: CVE-2026-52785 Ope… http://infoflow.cloud`

    Post summary

    The post announces a SQL injection vulnerability (CVE‑2026‑52785) in OpenProject’s timestamps functionality affecting versions before 17.3.3/17.4.1, referencing the CVE record.

    0001033
    89 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - OpenProject timestamps SQL injection via baseline comparison (CVE-2026-52785) OpenProject contains a SQL injection flaw in the work-package “timestamps” functionality used by the baseline comparison feature to fetch historic attributes. The root cause is improper input validation/unsafe query construction where the timestamps parameter is incorporated into SQL without adequate sanitization. An attacker can exploit this by sending crafted requests that include malicious SQL in the timestamps parameter to the baseline comparison endpoint, typically requiring only network access to the OpenProject instance (and any required app-level access for the feature). Successful exploitation can lead to database compromise, including data exfiltration and potential account takeover via stolen credentials/session data, and may enable destructive tampering with project records. 👉 Affected: openproject <17.3.3 and >=17.4.0 <17.4.1 | Upgrade to 17.3.3 or 17.4.1

    Post summary

    The post discloses a critical SQL injection flaw in OpenProject's baseline comparison feature, details the affected versions, and advises upgrading to patched releases.

    0000098
    231 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-52785 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject basel… https://www.cve.org/CVERecord?id=CVE-2026-52785

    Post summary

    The text reports a SQL injection vulnerability in OpenProject's timestamps functionality for versions prior to 17.3.3 and 17.4.1, with no PoC, exploit, or patch information provided.

    00000698
    57.7K followersView on X

Explore more