๐Ÿ” CVE Alert

CVE-2026-46386

CRITICAL 9.9

OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path reachable via the /my/two_factor_devices cookie reader This vulnerability is fixed in .

CWE CWE-502 CWE-798 CWE-1188 CWE-1392
Vendor opf
Product openproject
Published Jun 26, 2026
Stay Ahead of the Next One

Get instant alerts for opf openproject

Be the first to know when new critical vulnerabilities affecting opf openproject are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

opf / openproject
>= 8.3.0, < 17.2.4 >= 17.3.0, < 17.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/opf/openproject/security/advisories/GHSA-r85r-gjq2-f83r