Access Control Vulnerability in OpenPanel by OpenPanel Dev
CVE-2026-88893

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88893?

The OpenPanel application contains an access control vulnerability in its share lookup procedures, allowing unauthenticated users to bypass security measures. Exploiting this flaw, an attacker can obtain sensitive information such as argon2id password hashes and complete report configurations. This may lead to unauthorized access to protected data, enabling potential offline password cracking and unauthorized business intelligence gathering.

Affected Version(s)

openpanel 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

5ud0er
.