Access Control Bypass in OpenPanel by OpenPanel Dev
CVE-2026-88891
7.2HIGH
What is CVE-2026-88891?
The OpenPanel software contains a significant flaw that allows users with only read access to perform unauthorized actions. Specifically, 26 out of 29 mutating procedures fail to enforce appropriate access levels. This oversight permits users with read-only permissions to manipulate and delete project data, including reports and dashboards. Additionally, these users can initiate deletions of entire projects, publish private analytics through public links, and alter alert settings, thereby compromising the integrity and confidentiality of the affected projects.
Affected Version(s)
openpanel 0
