
Reproduction pack and PoC script for CVE-2026-52782, an authenticated IDOR in OpenProject project storage settings that hijacks Nextcloud/OneDrive folder ACLs.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-52782
OpenProject 17.3.2 — OpenProject GmbH
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, an IDOR through project storage settings allows a project-admin to hijack another project's managed Nextcloud or OneDrive folder.
| CVE | CVE-2026-52782 · CVE.org |
| CWE | CWE-639 |
| CVSS | Critical: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Product | OpenProject |
| Affected | all versions through 17.3.2 (inclusive) |
| Patched | 17.3.3 / 17.4.1 and later |
| Auth | authenticated (see source map) |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only · vendor/client disclosure pack, not a scanner |
Storages::ProjectStorages::BaseContract validates presence of project_folder_id for manual mode but never that it belongs to this project. Fixed in 17.3.3 / 17.4.1.
PATCH/projects/{identifier}/settings/project_storages/{id}Login as project-admin of project APATCH /projects/A/settings/project_storages/A_ps_id with victim project_folder_idStorages::ProjectStorages::UpdateService writes the idGET /api/v3/project_storages/A_ps_id shows GHSA52782-WITNESSAPI or edit HTML for the attacker ProjectStorage contains GHSA52782-WITNESS
Do this first: Update OpenProject to 17.3.3 / 17.4.1 or newer.
Verify after upgrade
CVE-2026-52782-Abraxas-Labs.py against the patched build: the mapped witness must not appear.If you cannot update immediately
Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.
python3 CVE-2026-52782-Abraxas-Labs.py
Success is the witness above in the response body. Generic 200 HTML is not it.
Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.
cd lab
docker compose up --force-recreate
Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.
# CVE-2026-52782
CWE: CWE-639
CVSS: Critical 9.9 (GHSA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
## Description
A project-admin can PATCH another project's managed Nextcloud/OneDrive folder id onto their own Storages::ProjectStorage. The next managed-folder sync overwrites that folder's ACL with the attacker project's members.
## Product
OpenProject 17.3.2 (fixed in 17.3.3 and 17.4.1). Lab oracle is a witness folder id, not a shell.
This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.
This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.