CVE-2026-103544
Received Received - Intake

Exposure of Data in OpenConstructionERP Al Provider Configuration

Vulnerability report for CVE-2026-103544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation results in exposure of data element to wrong session. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 15.0.0 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
datadrivenconstruction openconstructionerp to 14.8.1 (inc)
datadrivenconstruction openconstructionerp 15.0.0
datadrivenconstruction openconstructionerp 15.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-488 The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103544 is a vulnerability in OpenConstructionERP up to version 14.8.1. It involves a flaw in the AI provider configuration handler file ai_client.py where an authenticated user can manipulate AI settings to redirect requests to a malicious endpoint. This breaks user and tenant isolation, causing sensitive project data like PDFs and cost information to be intercepted by attackers.

Detection Guidance

Check if your OpenConstructionERP version is below 15.0.0 by running: pip show openconstructionerp or checking the version in the application. Inspect the ai_client.py file for improper session handling or global variable misuse in AI provider configurations.

Impact Analysis

This vulnerability allows attackers to intercept sensitive project data such as PDFs, project descriptions, and cost data by redirecting AI requests to malicious endpoints. It requires low privileges and no user interaction, making it exploitable remotely. The attack breaks user and tenant isolation, posing a high risk of data leakage in multi-user environments.

Compliance Impact

This vulnerability could lead to unauthorized access and exposure of sensitive project data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Data leakage risks from improper session boundaries could result in legal penalties, reputational damage, and loss of trust due to non-compliance with data protection standards.

Mitigation Strategies

Upgrade OpenConstructionERP to version 15.0.0 or later immediately. If upgrading is not possible, restrict access to the AI provider configuration settings and monitor network traffic for suspicious endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103544. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart