CVE-2026-52782 is an insecure direct object reference vulnerability in OpenProject affecting versions prior to 17.3.3 and 17.4.1. The flaw exists in the PATCH handling of the /projects/<A>/settings/project_storages/<A_ps_id> endpoint via the storages_project_storage[project_folder_id] parameter. A project administrator for one project can supply the project_folder_id belonging to another project that uses the same backing storage integration, causing the attacker-controlled Storages::ProjectStorage association to reference the victim project’s managed folder. On the next managed-folder synchronization, OpenProject updates the referenced Nextcloud or OneDrive folder ACLs using the attacker project’s membership, resulting in unauthorized reassignment of access to the victim folder.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This eight-file disclosure/lab repository contains a standalone Python proof of concept, documentation, AGPL-3.0 license, and a Docker-based vulnerable OpenProject 17.3.2 fixture. The Python script authenticates using the lab attacker account, obtains CSRF tokens, and submits a method-overridden PATCH to assign a victim project's managed folder ID to the attacker's ProjectStorage. It then queries the OpenProject v3 API, or the edit page, to confirm the `GHSA52782-WITNESS` value. The intended impact is cross-project managed-folder hijacking and potential later Nextcloud/OneDrive ACL replacement during synchronization, not remote code execution. The lab seeds two private projects, distinct project-admin users, one dummy Nextcloud storage, and two ProjectStorage records. `lab/docker-compose.yml` exposes OpenProject only on loopback at port 18097; `seed.rb` creates the fixture; and `run.sh` starts, waits for, seeds, and attempts to invoke a PoC. There are packaging inconsistencies: `run.sh` calls `poc.py`, which is not present in the listed repository (the actual script is named `CVE-2026-52782-Abraxas-Labs.py`), and the README's simple invocation/default local address does not align with the Compose port 18097. These issues may require manual correction to reproduce the lab, but do not alter the core HTTP IDOR logic. The exploit is classified as a POC because it provides a deterministic state-change witness rather than a customizable execution payload.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.