CVE-2026-34717 | opf openproject up to 17.2.2 Parameter operator.rb sql injection (GHSA-5rrm-6qmq-2364)
A vulnerability has been found in opf openproject up to 17.2.2 and classified as critical. This vulnerability affects unknown code in the library modules/reporting/lib/report/operator.rb of the component Parameter Handler. This manipulation causes sql injection.
This vulnerability appears as CVE-2026-34717. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.