A vulnerability labeled as problematic has been found in opf openproject up to 17.2.x. This impacts an unknown function. Executing a manipulation can lead to time-of-check time-of-use.
This vulnerability is tracked as CVE-2026-40896. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.