CVE-2026-23646
Last modified
CVE-2026-23646 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a session, it was not properly checked if the session belongs to the user. As the ID that is used to identify these session objects use incremental integers, users could iterate requests using `DELETE /my/sessions/:id` and thus unauthenticate other users. Users did not have access to any sensitive information (like browser identifier, IP addresses, etc) of other users that are stored in the session. The problem was patched in OpenProject versions 16.6.5 and 17.0.1. No known workarounds are available as this does not require any permissions or other that can temporarily be disabled.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openproject | Openproject | < 16.6.5 |
| Openproject | Openproject | 17.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23646?
How severe is CVE-2026-23646?
How do I fix CVE-2026-23646?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23636Kiteworks is a private data network (PDN). In Kiteworks Secu…7.2
- CVE-2026-23638Kiteworks is a private data network (PDN). Prior to version …6.5
- CVE-2026-2364If a legitimate user confirms a self-update prompt or initia…7.3
- CVE-2026-23643CakePHP is a rapid development framework for PHP. The Pagina…5.4
- CVE-2026-23644esm.sh is a no-build content delivery network (CDN) for web …7.5
- CVE-2026-23645SiYuan is self-hosted, open source personal knowledge manage…6.1
- CVE-2026-23647Glory RBG-100 recycler systems using the ISPK-08 software co…9.8
- CVE-2026-23648Glory RBG-100 recycler systems using the ISPK-08 software co…8.5
- CVE-2026-2365The Fluent Forms Pro plugin for WordPress is vulnerable to S…7.2
- CVE-2026-23651Permissive regular expression in Azure Compute Gallery allow…6.7
- CVE-2026-23652Improper neutralization of special elements used in a comman…9.8
- CVE-2026-23653Improper neutralization of special elements used in a comman…6.5
Are you affected by CVE-2026-23646?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
