CVE-2026-34717 is a critical SQL Injection vulnerability (CWE-89) affecting OpenProject versions prior to 17.2.3, stemming from unparameterized user input in the `=n` operator within SQL WHERE clauses. Rated 9.9 CRITICAL, this flaw allows a low-privileged authenticated user to remotely execute SQL commands with low complexity and no user interaction, leading to high impacts on data integrity and availability, and potential confidentiality compromise. There is currently no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB. While community discussion is minimal, organizations using affected OpenProject versions should prioritize upgrading to version 17.2.3 or later to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.2.3CPE matchmatch criteria | cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.