CVE-2026-22602 | opf openproject up to 16.6.1 API information disclosure (GHSA-7fvx-9h6h-g82j / EUVD-2026-1885)
A vulnerability identified as problematic has been detected in opf openproject up to 16.6.1. The impacted element is an unknown function of the component API. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-22602. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.