{"id":"CVE-2026-67529","summary":"OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)","details":"OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/costs/lib/api/v3/time_entries/time_entry_representer.rb and modules/costs/lib/api/v3/cost_entries/cost_entry_representer.rb without checking WorkPackage.visible or view_work_packages, allowing users with view_time_entries or view_cost_entries to read private work package subjects and ids. This issue is fixed in 17.6.0.","aliases":["GHSA-v3j7-vqwv-5w5q"],"modified":"2026-08-02T03:31:54.038923304Z","published":"2026-07-30T19:29:24.594Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67529.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-200","CWE-862"]},"references":[{"type":"WEB","url":"https://github.com/opf/openproject/releases/tag/v17.6.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67529.json"},{"type":"ADVISORY","url":"https://github.com/opf/openproject/security/advisories/GHSA-v3j7-vqwv-5w5q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67529"},{"type":"FIX","url":"https://github.com/opf/openproject/commit/9e9e562e516a647f35267df715d875f58b267c18"},{"type":"FIX","url":"https://github.com/opf/openproject/commit/c31c2f958c8e72a0d0d748d728221d57f3ef9001"},{"type":"FIX","url":"https://github.com/opf/openproject/pull/23888"},{"type":"FIX","url":"https://github.com/opf/openproject/pull/23936"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opf/openproject","events":[{"introduced":"0"},{"fixed":"9e9e562e516a647f35267df715d875f58b267c18"},{"fixed":"c31c2f958c8e72a0d0d748d728221d57f3ef9001"},{"fixed":"2ba1fce1196268ce5686ae308eceee744237440c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"17.6.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["11.2.1","v10.5","v9.0.0-pre","v5.0.4","sprint/2015_04","sprint/2015_03","sprint/2015_02","sprint/2015_01","sprint/2014_18","sprint/2014_16","sprint/2014_13","sprint/2014_12","sprint/2014_11","sprint/2014_10","sprint/2014_09","sprint/2014_08","2.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67529.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}