Cross-Tenant Authorization Flaw in OpenPanel by OpenPanel-dev
CVE-2026-85611
5.3MEDIUM
What is CVE-2026-85611?
OpenPanel versions prior to 2.3.0 are susceptible to a cross-tenant vulnerability in the report.getLayouts and report.resetLayout procedures. This flaw allows authenticated attackers to exploit the application by providing their own projectId alongside a guessable dashboardId, thereby bypassing authorization constraints. As a result, attackers can gain unauthorized access to sensitive report definitions or even delete dashboard layouts within other tenants, leading to serious security risks and data exposure.
Affected Version(s)
openpanel 0 < 2.3.0
openpanel 2.3.0
