API Authentication Bypass in OpenPanel by OpenPanel Developers
CVE-2026-93984
6.9MEDIUM
What is CVE-2026-93984?
The OpenPanel tracking API fails to properly verify the cryptographic hash of the client secret before granting authorization for revenue events and bot filtering. This oversight allows attackers, using only a public client ID, to supply arbitrary, fake secrets. Consequently, they can inject fraudulent revenue metrics and circumvent protective filters designed to detect bot activity. The lack of verification poses a serious risk to the integrity of revenue data and system security.
Affected Version(s)
openpanel 0
