CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67527

highCVSS 7.6covered by 1 sourcefirst seen 2026-07-30
OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve Storages::FileLink records by raw id, detach or hard-delete existing FileLinks, and re-parent FileLinks from other projects to an attacker-controlled work package, exposing origin filename, origin id, and MIME type metadata. This issue is fixed in 17.6.0.

⚡ Watch CVE-2026-67527

Get an email if CVE-2026-67527 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-67527

CVE.org record

Embed the live status

CVE-2026-67527 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67527 status](https://www.csirts.com/badge/CVE-2026-67527)](https://www.csirts.com/cve/CVE-2026-67527)