CVE-2026-67527 | OPF OpenProject up to 17.5.x File Link /api/v3/work_packages _links.fileLinks privileges management

SecurityVulns

A vulnerability classified as critical was found in OPF OpenProject up to 17.5.x. This issue affects some unknown processing of the file /api/v3/work_packages of the component File Link. Executing a manipulation of the argument _links.fileLinks can lead to improper privilege management.

This vulnerability is handled as CVE-2026-67527. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More