All Threat Alerts
criticalCVE Alert
CVE-2026-52782

Critical Vulnerability: CVE-2026-52782

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources. A project-admin in one project can hijack the managed Nextcloud or OneDrive folder of another project on the same storage by writing the victim project's project_folder_id into the attacker's Storages::ProjectStorage row.

Friday, June 26, 2026Vulnios Threat Intelligence
Share:

Vulnerability Snapshot

CVE-2026-52782 is rated CRITICAL โ€” exploitation is trivial or already observed in the wild and impact is severe. Patch immediately, not on the next maintenance window.

Executive Summary

Why It Matters

๐Ÿ›ก๏ธWhat Defenders Should Check

References & Sources

How Vulnios Detects This

Vulnios scans for this vulnerability using Trivy and Grype for SBOM-based CVE matching and Vulnios CVE feed continuous monitoring against your asset inventory. Run a scan against your environment to see whether you are exposed; findings are linked back to the original CVE record so triage starts with the patch path already known.

AI Security Advisor

Powered by Gemini

Get AI-powered security recommendations tailored to this specific threat โ€” including risk assessment, detection guidance, MITRE ATT&CK mapping, and actionable remediation steps.

Sources

Related Threat Alerts

Frequently Asked Questions

What is CVE-2026-52782?

CVE-2026-52782 is a critical-severity vulnerability tracked under the Common Vulnerabilities and Exposures program. OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project_storages/ via PATCH parameter "storages_

Am I affected?
How urgent is the response?
How do I remediate?
Where can I track exploitation activity?
How does Vulnios help with this?

Get instant alerts on Telegram

Join our public channel for real-time critical CVE alerts.

Follow @vulnios