OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permission check on the delete action was executed. This allowed all users in the application to delete work package budget assignments. This vulnerability is fixed in 17.2.0.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permission check on the delete action was executed. This allowed all users in the application to delete work package budget assignments. This vulnerability is fixed in 17.2.0. | |
| Title | OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgets | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-11T16:27:31.895Z
Updated: 2026-03-11T17:12:12.088Z
Reserved: 2026-03-04T17:23:59.798Z
Link: CVE-2026-30239
Updated: 2026-03-11T17:12:03.078Z
Status : Received
Published: 2026-03-11T17:16:57.773
Modified: 2026-03-11T17:16:57.773
Link: CVE-2026-30239
No data.