CVE-2026-22604 | opf openproject up to 16.6.1 /account/change_password password_change_user_id information disclosure (GHSA-q7qp-p3vw-j2fh / EUVD-2026-1883)
A vulnerability labeled as problematic has been found in opf openproject up to 16.6.1. This affects an unknown function of the file /account/change_password. The manipulation of the argument password_change_user_id results in information disclosure.
This vulnerability is reported as CVE-2026-22604. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.