{"document":{"category":"csaf_vex","csaf_version":"2.0","title":"CVE-2026-47193: OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks","publisher":{"category":"vendor","name":"HarborGuard Database","namespace":"https://database.harborguard.co"},"tracking":{"id":"CVE-2026-47193","status":"final","version":"1","initial_release_date":"2026-06-26T19:01:09.927Z","current_release_date":"2026-06-26T19:42:38.388Z","revision_history":[{"date":"2026-06-26T19:01:09.927Z","number":"1","summary":"Initial machine-readable export from HarborGuard."}]},"distribution":{"tlp":{"label":"WHITE"},"text":"Public CVE data; freely redistributable."},"notes":[{"category":"description","text":"OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.","title":"CVE description"}],"references":[{"category":"self","summary":"CVE-2026-47193 on HarborGuard Database","url":"https://database.harborguard.co/cve/CVE-2026-47193"},{"category":"external","summary":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-47193"},{"category":"external","summary":"https://github.com/opf/openproject/security/advisories/GHSA-f2rx-x2qj-2hgj","url":"https://github.com/opf/openproject/security/advisories/GHSA-f2rx-x2qj-2hgj"}]},"product_tree":{"branches":[{"category":"vendor","name":"opf","branches":[{"category":"product_name","name":"openproject","branches":[{"category":"product_version","name":"< 17.3.3","product":{"name":"opf openproject < 17.3.3","product_id":"CSAFPID-1","product_identification_helper":{"cpe":"cpe:2.3:a:opf:openproject:*:*:*:*:*:*:*:*"}}},{"category":"product_version","name":">= 17.4.0, < 17.4.1","product":{"name":"opf openproject >= 17.4.0, < 17.4.1","product_id":"CSAFPID-2","product_identification_helper":{"cpe":"cpe:2.3:a:opf:openproject:*:*:*:*:*:*:*:*"}}}]}]}]},"vulnerabilities":[{"cve":"CVE-2026-47193","title":"OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks","notes":[{"category":"description","text":"OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.","title":"CVE description"}],"product_status":{"known_affected":["CSAFPID-1","CSAFPID-2"]},"scores":[{"cvss_v3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH"},"products":["CSAFPID-1","CSAFPID-2"]}],"remediations":[{"category":"none_available","details":"No fixed version is published yet. Monitor the upstream advisory.","product_ids":["CSAFPID-1","CSAFPID-2"]}]}]}