Access Control Bypass in OpenPanel by OpenPanel Dev
CVE-2026-88891

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88891?

The OpenPanel software contains a significant flaw that allows users with only read access to perform unauthorized actions. Specifically, 26 out of 29 mutating procedures fail to enforce appropriate access levels. This oversight permits users with read-only permissions to manipulate and delete project data, including reports and dashboards. Additionally, these users can initiate deletions of entire projects, publish private analytics through public links, and alter alert settings, thereby compromising the integrity and confidentiality of the affected projects.

Affected Version(s)

openpanel 0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

5ud0er
.