CVE-2026-30239
Last modified
CVE-2026-30239 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permission check on the delete action was executed. This allowed all users in the application to delete work package budget assignments. This vulnerability is fixed in 17.2.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openproject | Openproject | < 17.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-30239?
How severe is CVE-2026-30239?
How do I fix CVE-2026-30239?
Are you affected by CVE-2026-30239?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
