A vulnerability was found in OPF OpenProject up to 17.5.x. It has been declared as problematic. Affected is an unknown function of the file modules/costs/lib/api/v3/time_entries/time_entry_representer.rb/modules/costs/lib/api/v3/cost_entries/cost_entry_representer.rb of the component Time Entry Representer/Cost Entry Representer. Executing a manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2026-67529. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.