Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55095— OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields

Quick assessment

Affected
opf openproject
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenProject 是一款开源、基于 Web 的项目管理软件。在 17.5.1 及更早版本中,经过身份验证的非管理员项目成员可以请求对原始 custom_field_ 项目属性进行就地编辑(inplace-edit)对话框。该对话框路径通过其原始标识符解析项目的自定义字段,但未强制执行正常的“仅管理员可见”(admin_only)可见性范围,并以只读模式渲染存储的自定义字段注释。这会导致隐藏的注释文本被泄露,但不会泄露自定义字段的值,也不允许写入或修改操作。该问题已在 17.6.0 版本中修复。

CVSS 5.3 · Medium EPSS 0.29% · P21

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
opf openproject < 17.6.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55095

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields
Source: CVE Program / CVE List V5
Vulnerability Description
OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-admin project member can request the inplace-edit dialog for a raw custom_field_ project attribute. The dialog path resolves the project custom field by its raw identifier without enforcing the normal admin_only visibility scope and renders the stored custom-field comment in read-only mode. This discloses hidden comment text but does not disclose the custom-field value or permit writes or mutation. This issue is reported as fixed in version 17.6.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
opf openproject < 17.6.0 -

II. Public POCs for CVE-2026-55095

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55095

登录查看更多情报信息。

Vendor Advisories for CVE-2026-55095 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55095

No comments yet


Leave a comment