Vulnerability Description
OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a session, it was not properly checked if the session belongs to the user. As the ID that is used to identify these session objects use incremental integers, users could iterate requests using `DELETE /my/sessions/:id` and thus unauthenticate other users. Users did not have access to any sensitive information (like browser identifier, IP addresses, etc) of other users that are stored in the session. The problem was patched in OpenProject versions 16.6.5 and 17.0.1. No known workarounds are available as this does not require any permissions or other that can temporarily be disabled.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openproject | Openproject | < 16.6.5 |
Related Weaknesses (CWE)
References
- https://github.com/opf/openproject/releases/tag/v16.6.5Release Notes
- https://github.com/opf/openproject/releases/tag/v17.0.1Release Notes
- https://github.com/opf/openproject/security/advisories/GHSA-w422-xf8f-v4vpVendor Advisory
FAQ
What is CVE-2026-23646?
CVE-2026-23646 is a vulnerability with a CVSS score of 6.5 (MEDIUM). OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settin...
How severe is CVE-2026-23646?
CVE-2026-23646 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23646?
Check the references section above for vendor advisories and patch information. Affected products include: Openproject Openproject.