Cross-Tenant Authorization Flaw in OpenPanel by OpenPanel-dev
CVE-2026-85611

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85611?

OpenPanel versions prior to 2.3.0 are susceptible to a cross-tenant vulnerability in the report.getLayouts and report.resetLayout procedures. This flaw allows authenticated attackers to exploit the application by providing their own projectId alongside a guessable dashboardId, thereby bypassing authorization constraints. As a result, attackers can gain unauthorized access to sensitive report definitions or even delete dashboard layouts within other tenants, leading to serious security risks and data exposure.

Affected Version(s)

openpanel 0 < 2.3.0

openpanel 2.3.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.