Unrated severityNVD Advisory· Published Jun 26, 2026· Updated Jun 27, 2026
OpenProject: Cache store poisoning leads to Remote Code Execution (RCE)
CVE-2026-52780
Description
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE). This vulnerability is fixed in 17.3.3 and 17.4.1.
Patches
Vulnerability mechanics
References
1- github.com/opf/openproject/security/advisories/GHSA-qj96-f42f-6336mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.