๐Ÿ” CVE Alert

CVE-2026-55095

UNKNOWN 0.0

OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-admin project member can request the inplace-edit dialog for a raw custom_field_ project attribute. The dialog path resolves the project custom field by its raw identifier without enforcing the normal admin_only visibility scope and renders the stored custom-field comment in read-only mode. This discloses hidden comment text but does not disclose the custom-field value or permit writes or mutation. This issue is reported as fixed in version 17.6.0.

CWE CWE-862
Vendor opf
Product openproject
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for opf openproject

Be the first to know when new unknown vulnerabilities affecting opf openproject are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

opf / openproject
< 17.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/opf/openproject/security/advisories/GHSA-63fg-pgqj-3qf8 github.com: https://github.com/opf/openproject/releases/tag/v17.6.0