Every story tagged Access Control Vulnerability, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
1 story · open in the command center
CVE-2026-67527 is a HIGH severity vulnerability (CVSS 7.6) in OpenProject versions prior to 17.6.0 that allows authenticated users to exploit authorization flaws to access, manipulate, and exfiltrate file metadata across projects, creating both data confidentiality and integrity risks. Organizations using OpenProject must urgently upgrade to version 17.6.0 to prevent privilege escalation attacks where users with limited permissions can perform unauthorized file operations and access sensitive metadata. This vulnerability highlights the critical importance of proper access controls in collaborative tools and demonstrates how API-level authorization gaps can expose project files and sensitive information across organizational boundaries.