OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3.
References
| Link | Resource |
|---|---|
| https://github.com/opf/openproject/releases/tag/v16.6.3 | Release Notes |
| https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j | Patch Vendor Advisory |
Configurations
History
14 Jan 2026, 22:27
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openproject openproject
Openproject |
|
| References | () https://github.com/opf/openproject/releases/tag/v16.6.3 - Release Notes | |
| References | () https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* |
10 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-10 02:15
Updated : 2026-01-14 22:27
NVD link : CVE-2026-22605
Mitre link : CVE-2026-22605
CVE.ORG link : CVE-2026-22605
JSON object : View
Products Affected
openproject
- openproject
CWE
CWE-284
Improper Access Control
