OpenProject Group Membership Enumeration Vulnerability

Vulnerability

A vulnerability in OpenProject prior to versions 17.0.1 and 16.6.5 allows users with the 'View Members' permission in any project to enumerate all groups and see their members. This issue arises from a failed permission check, enabling unauthorized visibility of group memberships.

Impact

Exploitation of this vulnerability allows for unauthorized enumeration of group memberships, revealing which users are part of specific groups.

Remediation

Users can upgrade to OpenProject versions 17.0.1 or 16.6.5 to address this vulnerability.

Added: Jan 19, 2026, 6:24 PM
Updated: Jan 19, 2026, 6:24 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
5.2
remediation
7.7
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.