Project query parameter vulnerability in Perses dashboard by open-source vendor
CVE-2026-63458
7.1HIGH
What is CVE-2026-63458?
Perses, an open-source dashboard and visualization tool for observability data, contains a vulnerability where an authenticated user with viewer access to one project can manipulate project data by altering the project query parameter in specific API endpoints. This allows users to bypass project-level tenant isolation, potentially accessing sensitive dashboards, data sources, and variables from other projects without proper authorization. This flaw compromises data confidentiality and integrity, making it crucial for users to upgrade to version 0.54.0-beta.3 or later to mitigate the risk.
Affected Version(s)
perses < 0.54.0-beta.3
