Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-52782 — Reproduction pack and PoC script for CVE-2026-52782, an authenticated IDOR in OpenProject project storage settings that hijacks Nextcloud/OneDrive folder ACLs. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-52782
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringSecurity VirtualizationWeb SecurityPenetration TestingLabs & Practice
GitHubabraxas/cve-2026-52782

CVE-2026-52782

Reproduction pack and PoC script for CVE-2026-52782, an authenticated IDOR in OpenProject project storage settings that hijacks Nextcloud/OneDrive folder ACLs.

12 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs — CVE-2026-52782

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  CVE-2026-52782

CVE-2026-52782

OpenProject 17.3.2 — OpenProject GmbH

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, an IDOR through project storage settings allows a project-admin to hijack another project's managed Nextcloud or OneDrive folder.

CVECVE-2026-52782 · CVE.org
CWECWE-639
CVSSCritical: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
ProductOpenProject
Affectedall versions through 17.3.2 (inclusive)
Patched17.3.3 / 17.4.1 and later
Authauthenticated (see source map)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only · vendor/client disclosure pack, not a scanner

Advisory (from the source map)

Storages::ProjectStorages::BaseContract validates presence of project_folder_id for manual mode but never that it belongs to this project. Fixed in 17.3.3 / 17.4.1.


Entry

  • Method: PATCH
  • Path: /projects/{identifier}/settings/project_storages/{id}
  • Router: Authenticated project-admin settings. UpdateContract does not check folder id ownership. Next managed-folder sync would rewrite Nextcloud/OneDrive ACL.
  • Notes: Authenticated CVE-2026-52782 CWE-639 OpenProject 17.3.2. Witness: GHSA52782-WITNESS on attacker ProjectStorage after PATCH. Not eval. Not a reverse shell.

Call chain

  • Login as project-admin of project A
  • PATCH /projects/A/settings/project_storages/A_ps_id with victim project_folder_id
  • Storages::ProjectStorages::UpdateService writes the id
  • GET /api/v3/project_storages/A_ps_id shows GHSA52782-WITNESS

Lab preconditions

  • OpenProject < 17.3.3 or 17.4.0
  • Project-admin of one project
  • A second project's ProjectStorage folder id on the same storage

Witness

API or edit HTML for the attacker ProjectStorage contains GHSA52782-WITNESS

Not success

  • eval/base64/system payload
  • reverse shell
  • patched 17.3.3

Patch / remediation

Do this first: Update OpenProject to 17.3.3 / 17.4.1 or newer.

Verify after upgrade

  • Re-run CVE-2026-52782-Abraxas-Labs.py against the patched build: the mapped witness must not appear.
  • Confirm the vendor advisory / changeset in the deployed tree (see references).
  • A WAF signature is delay, not a patch.

If you cannot update immediately

  • Disable or isolate the affected component.
  • Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).

Reproduction (authorized lab)

Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.

root@kitploit:~
python3 CVE-2026-52782-Abraxas-Labs.py

Success is the witness above in the response body. Generic 200 HTML is not it.


Lab images

Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.

  • lab/docker-compose.yml
  • lab/Dockerfile
  • lab/run.sh
  • lab/seed.rb
root@kitploit:~
cd lab
docker compose up --force-recreate

Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.


References

  • CVE-2026-52782 · NVD

  • CVE-2026-52782 · CVE.org

  • github.com/opf/openproject/security/advisories/GHSA-3vpx-94qx-xpw6

  • www.cve.org/CVERecord?id=CVE-2026-52782

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


Records (structured)

root@kitploit:~
# CVE-2026-52782

CWE: CWE-639
CVSS: Critical 9.9 (GHSA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

## Description

A project-admin can PATCH another project's managed Nextcloud/OneDrive folder id onto their own Storages::ProjectStorage. The next managed-folder sync overwrites that folder's ACL with the attacker project's members.

## Product

OpenProject 17.3.2 (fixed in 17.3.3 and 17.4.1). Lab oracle is a witness folder id, not a shell.

License

This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.


Disclaimer

This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool