CVE-2026-67528 | OPF OpenProject up to 17.5.x Custom Options /api/v3/custom_options ID information disclosure
A vulnerability, which was classified as problematic, has been found in OPF OpenProject up to 17.5.x. Impacted is an unknown function of the file /api/v3/custom_options of the component Custom Options. The manipulation of the argument ID leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-67528. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More