CVE-2026-22601
OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execute arbitrary command by configuring sendmail binary path and sending a test email. This issue has been patched in version 16.6.2.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22601.json, https://github.com/opf/openproject/releases/tag/v16.6.2, https://github.com/opf/openproject/security/advisories/GHSA-9vrv-7h26-c7jc, https://nvd.nist.gov/vuln/detail/CVE-2026-22601
