CVE-2026-30239
Last modified
CVE-2026-30239 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permission check on the delete action was executed. This allowed all users in the application to delete work package budget assignments. This vulnerability is fixed in 17.2.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openproject | Openproject | < 17.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-30239?
How severe is CVE-2026-30239?
How do I fix CVE-2026-30239?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30233OliveTin gives access to predefined shell commands from a we…4.3
- CVE-2026-30234OpenProject is an open-source, web-based project management …6.5
- CVE-2026-30235OpenProject is an open-source, web-based project management …6.5
- CVE-2026-30236OpenProject is an open-source, web-based project management …4.3
- CVE-2026-30237Group-Office is an enterprise customer relationship manageme…6.1
- CVE-2026-30238Group-Office is an enterprise customer relationship manageme…6.1
- CVE-2026-3024Stored Cross-Site Scripting (XSS) vulnerability in the Wakym…5.4
- CVE-2026-30240Budibase is a low code platform for creating internal tools,…8.1
- CVE-2026-30241Mercurius is a GraphQL adapter for Fastify. Prior to version…8.2
- CVE-2026-30242Plane is an an open-source project management tool. Prior to…8.5
- CVE-2026-30244Plane is an an open-source project management tool. Prior to…7.5
- CVE-2026-30246Fiber is a web framework for Go. In github.com/gofiber/fiber…6.5
Are you affected by CVE-2026-30239?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
