CVE-2026-22605

OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*

History

14 Jan 2026, 22:27

Type Values Removed Values Added
First Time Openproject openproject
Openproject
References () https://github.com/opf/openproject/releases/tag/v16.6.3 - () https://github.com/opf/openproject/releases/tag/v16.6.3 - Release Notes
References () https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j - () https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j - Patch, Vendor Advisory
CPE cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*

10 Jan 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-10 02:15

Updated : 2026-01-14 22:27


NVD link : CVE-2026-22605

Mitre link : CVE-2026-22605

CVE.ORG link : CVE-2026-22605


JSON object : View

Products Affected

openproject

  • openproject
CWE
CWE-284

Improper Access Control