CVE-2026-22605
Status: AnalyzedMedium (4.3)—
OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.23%
- Percentile among all scored CVEs: 13
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-284
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-22605",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-22605",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-01-12T19:15:19.921386Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "opf",
"product": "openproject",
"versions": [
{
"status": "affected",
"version": "< 16.6.3"
}
]
}
]
}
],
"published": "2026-01-10T02:15:49.487",
"references": [
{
"url": "https://github.com/opf/openproject/releases/tag/v16.6.3",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/opf/openproject/security/advisories/GHSA-fq4m-pxvm-8x2j",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allowed users with the View Meetings permission on any project, to access meeting details of meetings that belonged to projects, the user does not have access to. This issue has been patched in version 16.6.3."
},
{
"lang": "es",
"value": "OpenProject es un software de gestión de proyectos de código abierto y basado en la web. Las versiones de OpenProject anteriores a la versión 16.6.3 permitían a los usuarios con el permiso 'Ver reuniones' en cualquier proyecto, acceder a los detalles de reuniones que pertenecían a proyectos a los que el usuario no tenía acceso. Este problema ha sido parcheado en la versión 16.6.3."
}
],
"lastModified": "2026-06-17T10:20:09.000",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2267B9E-E4A8-4C9D-9BEF-BE744BAEDF0E",
"versionEndExcluding": "16.6.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}