{"id":81132,"date":"2026-06-26T22:31:09","date_gmt":"2026-06-26T19:01:09","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-47193-openproject-journal-diff-endpoint-bypasses-object-journal-and-field-visibility-checks\/"},"modified":"2026-06-26T22:31:09","modified_gmt":"2026-06-26T19:01:09","slug":"cve-2026-47193-openproject-journal-diff-endpoint-bypasses-object-journal-and-field-visibility-checks","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-47193-openproject-journal-diff-endpoint-bypasses-object-journal-and-field-visibility-checks\/","title":{"rendered":"CVE-2026-47193 &#8211; OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks"},"content":{"rendered":"<p>CVE ID :CVE-2026-47193<\/p>\n<p>  Published : June 26, 2026, 7:01 p.m. | 44\u00a0minutes ago<\/p>\n<p>  Description :OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.<\/p>\n<p>  Severity: 0.0 | NA<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-47193 Published : June 26, 2026, 7:01 p.m. | 44\u00a0minutes ago Description :OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1. Severity: 0.0 | NA Visit the &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-81132","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=81132"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81132\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=81132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=81132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=81132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}