OpenProject Improper Authentication Vulnerability Allows Unauthorized Wiki Page Creation

Vulnerability

A vulnerability in OpenProject prior to versions 17.0.5 and 17.1.2 allows attackers to create wiki pages in projects they do not have permission to access. This issue arises from an improperly authenticated request that bypasses project membership checks. The vulnerability has been patched in versions 17.0.5 and 17.1.2.

Impact

Exploitation of this vulnerability allows for unauthorized creation of wiki pages in restricted projects, potentially leading to misinformation or disruption within project management workflows.

Remediation

Users are advised to update to OpenProject versions 17.0.5 or 17.1.2.

Added: Mar 5, 2026, 7:23 PM
Updated: Mar 5, 2026, 7:45 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
5.2
remediation
7.7
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.