CVE-2026-30239

Published Mar 11, 2026

Last updated 25 days ago

Overview

Description
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different budget. This action was performed before the permission check on the delete action was executed. This allowed all users in the application to delete work package budget assignments. This vulnerability is fixed in 17.2.0.
Source
security-advisories@github.com
NVD status
Analyzed
Products
openproject

Risk scores

CVSS 3.1

Type
Primary
Base score
7.1
Impact score
4.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-863

Social media

Hype score
Not currently trending

Configurations