CVE-2026-23721 | opf openproject up to 16.6.4/17.0.0 Group Member authorization (GHSA-vj77-wrc2-5h5h / EUVD-2026-3307)
A vulnerability was found in opf openproject up to 16.6.4/17.0.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Group Member Handler. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2026-23721. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.